Advisory
A note with CVSS 8.8 for component HAN-DB-SEC was released by SAP on 13.01.2026. The correction/advisory 3691059 was described with "[CVE-2026-0492] Privilege escalation vulnerability in SAP HANA database" and affects the system type HANA platform.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process.
The vulnerability addressed is escalation of privileges within HANA platform.
Risk specification
The HANA database allows an authenticated attacker to impersonate any user, which could result in unauthorized administrative access.
Solution
This correction prevents unauthorized privilege escalation.
Affected System
SAP HANA is a high-performance in-memory database and the basis for a so called "Real-Time Data Platform". SAP HANA allows online transaction processing (OLTP) and online analytical processing (OLAP) on one system. SAP HANA Extended Application Services (aka SAP HANA XS) is a key aspect of SAP HANA as a platform.
Additonal resources
The advisory is valid for
- HDB 2.00 15
