high2026-08-11SAP SCMCVE-2026-34259
OS Command Injection in SAP Forecasting and Replenishment
SAP Forecasting and Replenishment
Our Take
OS command injection is a high-confidence exploitable vulnerability — it is one of the cleanest attack paths if the server is reachable. If you run SAP Forecasting and Replenishment in your supply chain landscape, schedule this within two weeks.
Vulnerability Detail
An OS command injection vulnerability in SAP Forecasting and Replenishment allows an authenticated attacker to inject operating system commands through unsanitised input, achieving arbitrary command execution on the underlying server. This compromises the integrity and availability of the F&R system and potentially the systems it integrates with.
Patch Action
Apply SAP Note 3732471. Verify affected versions in the official SAP Note.
Patch Info