---
schema: 1
kind: vulnerability
title: "CVE-2026-34263 / CVE-2026-34260 — SAP Commerce Cloud pre-auth RCE, S/4HANA Enterprise Search SQL injection"
headline: "CVE-2026-34263 / CVE-2026-34260 — SAP Commerce Cloud pre-auth RCE, S/4HANA Enterprise Search SQL injection"
summary: "SAP Commerce Cloud pre-auth RCE plus S/4HANA Enterprise Search SQLi. CVE-2026-34263 (CVSS 9.6) is unauthenticated arbitrary code injection via overly permissive Spring Security ordering on the cloud-config endpoint; CVE-2026-34260 (CVSS 9.6) is post-auth SQL injection in the Enterprise Search ABAP component — enabled by default. SAP Commerce and S/4HANA are core to Swiss federal procurement (NOVE/SUPERB programmes) and EU institutional ERP (Onapsis, 2026-05-12; SecurityWeek, 2026-05-12)."
discovered_at: "2026-05-13T05:00:05Z"
event_date: 2026-05-12
run_id: 2026-05-13-c148b9a5
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - pre-auth
  - rce
  - patch-available
regions:
  - global
sectors: []
entities:
  - "campaign:mini-shai-hulud"
cves:
  - id: CVE-2026-34263
    cvss: "9.6"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-34260
    cvss: "9.6"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://onapsis.com/blog/sap-security-patch-day-may-2026/"
    publisher: "Onapsis, 2026-05-12"
    role: primary
  - url: "https://www.securityweek.com/sap-patches-critical-s-4hana-commerce-vulnerabilities/"
    publisher: "SecurityWeek, 2026-05-12"
    role: corroborating
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12565"
    publisher: "NCSC-CH Security Hub #12565, 2026-05-12"
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Apply SAP May 2026 Security Patch Day on Commerce Cloud and S/4HANA.** CVE-2026-34263 (Commerce Cloud, pre-auth RCE, CVSS 9.6) is emergency-priority because the cloud-config endpoint is internet-facing in many deployments — apply SAP Note 3733064. CVE-2026-34260 (S/4HANA Enterprise Search ABAP, post-auth SQL injection, CVSS 9.6) before next maintenance window. Cross-reference SAP HotNews #3747787 against any SAP CAP packages in your build pipeline. See § 2"
migrated_from: briefs/2026-05-13.md
---

SAP's May 2026 Security Patch Day (2026-05-12) released 17 patches, three HotNews ([Onapsis, 2026-05-12](https://onapsis.com/blog/sap-security-patch-day-may-2026/); [SecurityWeek, 2026-05-12](https://www.securityweek.com/sap-patches-critical-s-4hana-commerce-vulnerabilities/); [NCSC-CH Security Hub #12565, 2026-05-12](https://security-hub.ncsc.admin.ch/#/posts/12565)). **CVE-2026-34263** (CVSS 9.6, CWE-459 Incomplete Cleanup) is a missing authentication on SAP Commerce Cloud's cloud-config endpoint caused by overly permissive Spring Security ordering — an unauthenticated attacker can upload arbitrary configuration and reach server-side code execution. Affects HY_COM 2205 and COM_CLOUD 2211 / 2211-JDK21. **CVE-2026-34260** (CVSS 9.6) is SQL injection in the SAP S/4HANA Enterprise Search for ABAP component, missing input validation; affected SAP_BASIS 751–758 and 816. Authentication required but the blast radius is full database read / write. **CVE-2026-34259** (CVSS 8.2) is OS-command injection in SAP Forecasting & Replenishment (authenticated). A third HotNews note (SAP #3747787) acknowledges the impact of the Mini Shai-Hulud npm worm ( on SAP Cloud Application Programming (CAP) packages. No ITW exploitation reported. SAP S/4HANA is the backbone ERP for Swiss federal administration (NOVE / SUPERB programmes) and many EU institutions; SAP Commerce Cloud commonly powers e-government procurement portals — both of which sit close to the public-internet boundary. Detection concepts mapped to `T1190` (Commerce Cloud) and `T1190` + `T1213` (S/4HANA): instrument the SAP HTTP front-end logs for Spring Security rule-bypass patterns on cloud-config endpoints; audit ABAP Enterprise Search call logs for anomalous SQL-syntax payloads in user-input fields. Hardening: apply SAP Notes via the May 2026 patch day; disable Enterprise Search ABAP if not in operational use; restrict Commerce Cloud cloud-config endpoint to administrative networks.
