An authenticated attacker in SAP CRM and SAP S/4HANA ...
Critical severity
Unreviewed
Published
Feb 10, 2026
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Feb 10, 2026
Published to the GitHub Advisory Database
Feb 10, 2026
An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.
References