CVE-2026-34262 is an information disclosure vulnerability affecting SAP HANA Cockpit and HANA Database Explorer that could allow authenticated users to access sensitive data they are not authorized to view. The vulnerability has a CVSS score of 5.0 (Medium severity) and requires low attack complexity with network accessibility, meaning an attacker with valid credentials can exploit it remotely without user interaction. The impact is limited to confidentiality breach with no impact on system integrity or availability, as indicated by the CVSS vector and the restricted scope of the vulnerability. Currently, this vulnerability is not listed on the KEV catalog and shows minimal community attention with an extremely low EPSS score of 0.0003, suggesting active exploitation in the wild is unlikely at this time. Organizations using affected SAP HANA products should apply available patches, though the risk should be assessed as relatively low compared to other vulnerabilities given the authentication requirement and limited attack surface.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.18.2CPE matchmatch criteria | cpe:2.3:a:sap:hana_cockpit:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:sap:hana_database_explorer:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.