Junglewise Threat Intelligence

CVE-2026-34259: SAP Forecasting & Replenishment OS command execution

CVE-2026-34259 · Severity: high · CVSS 8.2 · Published 2026-05-12

Vendors: SAP.

Executive brief

SAP Forecasting & Replenishment, a tool used by retail organizations to optimize inventory and supply chain planning, contains a vulnerability that allows an administrative user to execute unauthorized operating system commands. While the attacker must already have high-level access, this flaw allows them to bypass application restrictions to gain full control over the underlying server. This could lead to the theft of sensitive supply chain data, permanent deletion of system files, or a complete shutdown of the replenishment service.

Technical details

An OS Command Execution vulnerability (CWE-77) exists in SAP Forecasting & Replenishment due to improper neutralization of special elements in a non-remote-enabled function. An authenticated attacker with administrative privileges can exploit this flaw to execute arbitrary commands at the operating system level. The attack vector is classified as local (AV:L), meaning the attacker requires local access or existing high-level credentials to the application environment. Successful exploitation results in a complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H) with scope change (S:C), potentially allowing the attacker to pivot from the application to the underlying host. SAP has released security note 3732471 to address this issue.

Affected products

  • SAP Forecasting & Replenishment

Timeline

  • 2026-05-12: advisory: Initial disclosure by SAP and NVD
  • 2026-05-12: patched: Fix released in SAP Security Note 3732471

References