Advisory
On 12.05.2026 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within HANA platform.
SAP Note 3726962 addresses "3726962 - [CVE-2026-40131] SQL Injection vulnerability in SAP HANA Deployment Infrastructure (HDI) deploy library" to prevent sql injection (read) with a low risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance, the team suggests.
Risk specification
SAP HANA Deployment Infrastructure (HDI Deploy) allows an authenticated high-privileged attacker to inject SQL through dynamically constructed queries, resulting in unauthorized read access to data and reduced availability of the application.
Solution
Input passed to the affected parameter is now sanitized to prevent altered SQL statements from being passed to the database.
Affected System
SAP HANA is a high-performance in-memory database and the basis for a so called "Real-Time Data Platform". SAP HANA allows online transaction processing (OLTP) and online analytical processing (OLAP) on one system. SAP HANA Extended Application Services (aka SAP HANA XS) is a key aspect of SAP HANA as a platform.
Additonal resources
The advisory is valid for
- XS_HDI_DEPLOYER 1.00
