Advisory
A note with CVSS 5.0 for component HAN-CPT-CPT2-DBX was released by SAP on 14.04.2026. The correction/advisory 3730639 was described with "3730639 - [CVE-2026-34262] Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer" and affects the system type HANA platform.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is information disclosure within HANA platform.
Information disclosure is when an application fails to properly protect sensitive and confidential information from
parties that are not supposed to have access to the subject matter in normal circumstances.
Carefully review every information disclosure vulnerablity in regards to disclosure obligations post-GDPR for
‘Personal data’ under the Data Protection Act 2018.
Risk specification
SAP HANA Cockpit and HANA Database Explorer allow an authenticated attacker to retrieve the server's mTLS private key in plaintext through an API endpoint, potentially resulting in exposure of cryptographic material.
Solution
The issue has been resolved by preventing the exposure of sensitive information in plaintext within API payloads.
Affected System
SAP HANA is a high-performance in-memory database and the basis for a so called "Real-Time Data Platform". SAP HANA allows online transaction processing (OLTP) and online analytical processing (OLAP) on one system. SAP HANA Extended Application Services (aka SAP HANA XS) is a key aspect of SAP HANA as a platform.
Additonal resources
The advisory is valid for
- SAP_HANA_COCKPIT 2.0
