CVE-2026-0492
SAP HANA vulnerability analysis and mitigation

Overview

CVE-2026-0492 is a privilege escalation vulnerability in SAP HANA Database version 2.00 that allows an authenticated attacker with valid credentials of any user to switch to another user account, potentially gaining administrative access. The vulnerability was received from SAP SE on January 12, 2026, and published to NVD on January 13, 2026, with initial analysis completed on January 27, 2026. It carries a CVSS v3.1 base score of 8.8 (High), assigned by SAP SE (SAP Security Notes, Red Hat CVE).

Technical details

The root cause is classified as CWE-306 (Missing Authentication for Critical Function), meaning SAP HANA fails to enforce adequate authentication controls when switching user contexts, allowing a low-privileged authenticated user to assume the identity of another user — including administrative accounts. The attack vector is network-based, requires low privileges, no user interaction, and low attack complexity, making it straightforward to exploit once an attacker has any valid database credential. The specific internal mechanism (e.g., affected API endpoint or SQL command) is detailed in SAP Security Note 3691059, which requires SAP portal access (SAP Patch Note, SAP Security Patch Day).

Impact

Successful exploitation results in a total compromise of the affected SAP HANA database system's confidentiality, integrity, and availability. An attacker who escalates to an administrative account can read, modify, or delete all database contents — including sensitive financial, HR, and business data typically stored in SAP HANA environments — and disrupt database services. Given SAP HANA's role as a core data platform in enterprise environments, compromise could enable lateral movement to connected SAP applications such as S/4HANA (Red Hat CVE, Feedly Intelligence).

Mitigation and workarounds

SAP has released a patch addressing CVE-2026-0492 as part of SAP Security Patch Day January 2026; organizations should apply SAP Security Note 3691059 immediately to affected SAP HANA Database 2.00 installations (SAP Security Notes, SAP Security Patch Day). As interim mitigations, administrators should implement strict network access controls to limit who can authenticate to the SAP HANA database, enforce the principle of least privilege for all database accounts, and monitor for anomalous user-switching activity in database audit logs. Organizations should also review SAP HANA audit logging configurations to ensure user context changes are captured and alerted upon.

Community reactions

The vulnerability received broad coverage as part of SAP's January 2026 Patch Day, which addressed 17 security notes in total. Security outlets including CyberSecurityNews, GBHackers, SecurityBridge, and Heise covered the patch day, highlighting CVE-2026-0492 as one of the more severe issues due to its potential for total system compromise (CyberSecurityNews, SecurityBridge, Heise). TheHackerWire specifically highlighted the "any user to admin" escalation path on social media, drawing attention from the SAP security community (TheHackerWire).

Additional resources


SourceThis report was generated using AI

Related SAP HANA vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-40309CRITICAL9.8
  • SAP HANA logoSAP HANA
  • cpe:2.3:a:sap:hana_database
NoYesSep 12, 2023
CVE-2021-21484CRITICAL9.8
  • SAP HANA logoSAP HANA
  • cpe:2.3:a:sap:hana
NoYesMar 09, 2021
CVE-2026-0492HIGH8.8
  • SAP HANA logoSAP HANA
  • cpe:2.3:a:sap:hana_database
NoYesJan 13, 2026
CVE-2023-40308HIGH7.5
  • SAP HANA logoSAP HANA
  • cpe:2.3:a:sap:hana_database
NoYesSep 12, 2023
CVE-2021-21474MEDIUM6.5
  • SAP HANA logoSAP HANA
  • cpe:2.3:a:sap:hana_database
NoYesFeb 09, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management