---
cve: "CVE-2026-34261"
severity: "MEDIUM"
cvss: 6.5
epss: "21%"
vendor: "SAP_SE"
kev: false
exploited: false
published: "2026-04-14 01:16:03"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-12T01:53:16+02:00"
---

# CVE-2026-34261

> 6.5 MEDIUM

## Beschreibung

Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could make unauthorized calls to certain remote function modules, potentially accessing sensitive information beyond their intended permissions. This vulnerability affects confidentiality, with no impact on integrity and availability.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://me.sap.com/notes/3705094>
- <https://url.sap/sapsecuritypatchday>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-34261) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
