CVE-2026-34261Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could make unauthorized calls to certain remote function modules, potentially accessing sensitive information beyond their intended permissions. This vulnerability affects confidentiality, with no impact on integrity and availability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-14: 3Technical Details · 2026-04-14: 304-14
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-34261 📊 Severity: 6.5 🚨 Risk Level: Medium 🧩 Affects: Sap Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-34261 #CVE-2026-34261 #CVE #Medium #Sap #CyberSecurity #InfoSec https://t.co/eNa0VkM8Wj

    Post summary

    The tweet simply announces CVE-2026-34261, reporting a medium severity (6.5) affecting SAP, without providing PoC, exploit, or patch details.

    0000030
    137 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-34261 Unauthorized Remote Function Module Access in SAP Business Analytics and Content Management https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34261

    Post summary

    The entry provides a CVE identifier with a high‑level description and a link to detailed information, but offers no specifics on patches, exploitation, or mitigation.

    0000050
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34261 Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could make unauthorized calls to certain remote funct… https://www.cve.org/CVERecord?id=CVE-2026-34261

    Post summary

    The text discloses a missing authorization check in SAP Business Analytics and SAP Content Management that allows authenticated users to invoke unauthorized remote function calls.

    0000078
    57.2K followersView on X

Explore more