Input Injection Vulnerability in SAP S/4HANA by SAP
CVE-2026-44766
6.5MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-44766?
A vulnerability exists in SAP S/4HANA (Intercompany Matching and Reconciliation) that permits a low-privileged authenticated user to inject malicious input. This input may be executed by the database without adequate validation mechanisms. Consequently, this can lead to unauthorized access to sensitive information, posing a significant threat to data confidentiality. However, the integrity and availability of the application remain unaffected.
Affected Version(s)
SAP S/4HANA (Intercompany Matching and Reconciliation) SAPSCORE 136
SAP S/4HANA (Intercompany Matching and Reconciliation) S4CORE 104
SAP S/4HANA (Intercompany Matching and Reconciliation) 105