• News/
  • bleepingcomputer-20260512110455

SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA

BleepingComputer
·
Sergiu Gatlan
·
Published May 12, 2026
·
Updated

SAP has released the May 2026 security updates addressing 15 vulnerabilities across multiple products, including two critical flaws in Commerce Cloud and S/4HANA. Commerce Cloud is an enterprise-grade e-commerce platform used by online stores owned by large retailers and global brands, while S/4HANA is a cloud-based Enterprise Resource Planning (ERP) suite that will replace the company's on-premises ECC ERP system. Tracked as CVE-2026-34263, the first critical flaw is a missing authentication check in SAP Commerce Cloud that allows unauthenticated attackers to execute code on vulnerable servers. "Due to improper Spring Security configuration, SAP Commerce cloud allows an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application," SAP says. The second critical vulnerability (CVE-2026-34260) enables attackers with basic privileges to inject malicious SQL statements in low-complexity SQL injection attacks. "The application directly concatenates this malicious user input into SQL queries, which are then passed to the underlying database without proper validation or sanitization," according to SAP. "Upon successful exploitation, an attacker may gain unauthorized access to sensitive database information and could potentially crash the application. This vulnerability has a high impact on the confidentiality and availab...

Read full article

Affected Software

2 affected components
SAP Commerce Cloud
SAP S/4HANA
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the security updates released by SAP in May 2026 to address vulnerabilities in Commerce Cloud and S/4HANA.

2

What security implications are discussed in the article?

The article highlights critical vulnerabilities identified in SAP's Commerce Cloud and S/4HANA products that could potentially be exploited.

3

What products or software are affected by the vulnerabilities?

The affected products include SAP Commerce Cloud and SAP S/4HANA.

4

How many vulnerabilities were addressed in the recent updates?

SAP addressed a total of 15 vulnerabilities in the May 2026 security updates.

5

What types of flaws were identified in the Commerce Cloud and S/4HANA?

Two critical flaws were identified in both SAP Commerce Cloud and S/4HANA products.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203