CVE-2026-44753

LOW

SAP HANA User Self Service - Account and Email Enumeration

Title source: manual
STIX 2.1

Description

SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low impact on confidentiality, with no impact on integrity and availability of the application.

Scores

CVSS v3 3.7
EPSS 0.0022
EPSS Percentile 12.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-204
Status published
Products (1)
SAP_SE/SAP HANA Extended Application Services classic model (User Self Service) HDB 2.00
Published Jul 14, 2026
Tracked Since Jul 14, 2026