Input Validation Flaw in SAP S/4HANA Private Cloud Financials General Ledger
CVE-2026-0501
9.9CRITICAL
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 January 2026
What is CVE-2026-0501?
A vulnerability exists in SAP S/4HANA Private Cloud and On-Premise that stems from insufficient input validation, potentially allowing an authenticated user to craft and execute malicious SQL queries. This could lead to unauthorized access to backend database data, resulting in unauthorized reading, modifying, or deletion of sensitive information. The flaw poses significant risks to the application's confidentiality, integrity, and availability.
Affected Version(s)
SAP S/4HANA Private Cloud and On-Premise (Financials � General Ledger) S4CORE 102
SAP S/4HANA Private Cloud and On-Premise (Financials � General Ledger) 103
SAP S/4HANA Private Cloud and On-Premise (Financials � General Ledger) 104