Vulnerability in SAP S/4HANA Finance Advanced Payment Management
CVE-2026-76959
4.6MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-76959?
SAP S/4HANA Finance's Advanced Payment Management feature lacks adequate protection against Cross-Site Request Forgery (CSRF) for specific requests. This vulnerability allows attackers with low privileges to craft malicious links or web pages. If an authenticated user engages with these malicious elements, they may unintentionally execute actions on the web server under the user's identity. While this could compromise the confidentiality and integrity of certain actions, it does not affect the system's overall availability.
Affected Version(s)
SAP S/4HANA (Finance for Advanced Payment Management) UIAPFI70 800
SAP S/4HANA (Finance for Advanced Payment Management) 900
SAP S/4HANA (Finance for Advanced Payment Management) 901