CVE-2026-34259: OS Command Injection Vulnerability in SAP Forecasting & Replenishment
Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administrative authorizations could abuse a non-remote-enabled function to execute arbitrary operating system commands. Successful exploitation could allow the attacker to read or modify any system data or shut down the system, resulting in a complete compromise of confidentiality, integrity, and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34259?
CVE-2026-34259 is classified as a critical severity vulnerability due to its potential to allow authenticated attackers to execute arbitrary operating system commands.
How do I fix CVE-2026-34259?
To fix CVE-2026-34259, apply the latest security patches released by SAP for SAP Forecasting & Replenishment.
Who is affected by CVE-2026-34259?
CVE-2026-34259 affects users of SAP Forecasting & Replenishment who have administrative authorizations.
What type of vulnerability is CVE-2026-34259?
CVE-2026-34259 is an OS Command Injection vulnerability that allows attackers to execute commands on the operating system.
Can CVE-2026-34259 be exploited remotely?
CVE-2026-34259 cannot be exploited remotely as it requires authenticated access to the affected SAP application.