Cross-Site Request Forgery Vulnerability in SAP S/4HANA Finance Advanced Payment Management
CVE-2026-76960
3.5LOW
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-76960?
The vulnerability in SAP S/4HANA Finance's Advanced Payment Management component arises from insufficient Cross-Site Request Forgery (CSRF) protection. Attackers with low privileges can exploit this weakness by crafting malicious links or web pages. If an authenticated user interacts with such content, unauthorized actions may be executed on the server as if they were the user. This security flaw could lead to a compromise of user actions and potentially affect confidentiality and integrity, while availability remains unaffected.
Affected Version(s)
SAP S/4HANA (Finance for Advanced Payment Management) S4CORE 105
SAP S/4HANA (Finance for Advanced Payment Management) 106
SAP S/4HANA (Finance for Advanced Payment Management) 107