Skip to main content

Exposed Private Key of X.509 Certificate in SAP HANA Cockpit & SAP HANA Database Explorer

SAP HANA Cockpit users with access to the Database Explorer could retrieve the private keys of X.509 certificates. This could be used to impersonate the application server on network level, allowing an attacker to obtain user credentials or other sensitive data. The software patch provided by SAP does not suffice to completely mitigate the security risk. The affected X.509 certificates and corresponding private keys need to be revoked and rotated manually.
CVE-2026-34262

Read the full advisory here

Share this article

Dive deeper

  • Service Focus

Cybersecurity

  • Magazine

Digital security magazine 17

  • Magazine

Digital security magazine 18th Edition