CVE-2026-0501
Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute crafted SQL queries to read, modify, and delete bac...
Affects 0 products across 2 vendors.
Attacker inserts SQL commands into application queries through user-controlled input, allowing unauthorized database access.
Show all 6
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
CVE-2026-0501 involves insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), allowing authenticated users to execute crafted SQL queries, impacting confidentiality, integrity, and availability.
BSID: BS-2026-GLOBAL-059183-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-0501?
What is the CVSS score for CVE-2026-0501?
Is CVE-2026-0501 actively exploited?
How do I remediate CVE-2026-0501?
What systems are affected by CVE-2026-0501?
| CVE ID | CVE-2026-0501 |
|---|---|
| BSID | BS-2026-GLOBAL-059183-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| Published | 2026-01-13 |
| Last Modified | 2026-04-15 |
| ICS Relevance | 0% |
| Weakness (CWE) | |
| Source | NVD |
Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute crafted SQL queries to read, modify, and delete backend database data. This leads to a high impact on the confidentiality, integrity, and availability of the application.
Source: NIST NVD / MITRE CVE Database
An authenticated user can exploit this vulnerability by submitting specially crafted SQL queries to the application, which can lead to unauthorized data access, modification, and deletion.
Exploitation Likelihood: CRITICAL
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | b6b8bd46476c90ee7ba92394cdb7fec2479c4c8aaf29c50c826aa1a08f123640f3a145e04168add2e5b7372389383bb65783549cd962facc756405bb0b97a5d7 |
Critical Severity - Know Your Exposure
A CVSS 9.9 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →