Vulnerability in SAP S/4HANA Finance Advanced Payment Management
CVE-2026-76959

4.6MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
8 September 2026

What is CVE-2026-76959?

SAP S/4HANA Finance's Advanced Payment Management feature lacks adequate protection against Cross-Site Request Forgery (CSRF) for specific requests. This vulnerability allows attackers with low privileges to craft malicious links or web pages. If an authenticated user engages with these malicious elements, they may unintentionally execute actions on the web server under the user's identity. While this could compromise the confidentiality and integrity of certain actions, it does not affect the system's overall availability.

Affected Version(s)

SAP S/4HANA (Finance for Advanced Payment Management) UIAPFI70 800

SAP S/4HANA (Finance for Advanced Payment Management) 900

SAP S/4HANA (Finance for Advanced Payment Management) 901

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.