CVE-2026-0501: SQL Injection Vulnerability in SAP S/4HANA Private Cloud and On-Premise (Financials � General Ledger)
Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute crafted SQL queries to read, modify, and delete backend database data. This leads to a high impact on the confidentiality, integrity, and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0501?
CVE-2026-0501 is considered a high-severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2026-0501?
To fix CVE-2026-0501, apply the latest security patches provided by SAP for S/4HANA.
Who is affected by CVE-2026-0501?
CVE-2026-0501 affects authenticated users of SAP S/4HANA Private Cloud and On-Premise versions specifically in Financials General Ledger.
What are the potential impacts of CVE-2026-0501?
Successful exploitation of CVE-2026-0501 allows attackers to read, modify, and delete sensitive financial data.
Is user authentication sufficient to mitigate CVE-2026-0501?
No, simply having user authentication is not sufficient, as the vulnerability arises from inadequate input validation.