high2026-08-11SAP SCMCVE-2026-34259

OS Command Injection in SAP Forecasting and Replenishment

SAP Forecasting and Replenishment

Our Take

OS command injection is a high-confidence exploitable vulnerability — it is one of the cleanest attack paths if the server is reachable. If you run SAP Forecasting and Replenishment in your supply chain landscape, schedule this within two weeks.

Vulnerability Detail

An OS command injection vulnerability in SAP Forecasting and Replenishment allows an authenticated attacker to inject operating system commands through unsanitised input, achieving arbitrary command execution on the underlying server. This compromises the integrity and availability of the F&R system and potentially the systems it integrates with.

Patch Action

Apply SAP Note 3732471. Verify affected versions in the official SAP Note.

Patch Info

CVSS Score

8.2

SAP Note

3732471

CVE

CVE-2026-34259

Published

2026-08-11

← All patches