Cross-Site Request Forgery Vulnerability in SAP S/4HANA Finance Advanced Payment Management
CVE-2026-76960

3.5LOW

Key Information:

Vendor

SAP

Vendor
CVE Published:
8 September 2026

What is CVE-2026-76960?

The vulnerability in SAP S/4HANA Finance's Advanced Payment Management component arises from insufficient Cross-Site Request Forgery (CSRF) protection. Attackers with low privileges can exploit this weakness by crafting malicious links or web pages. If an authenticated user interacts with such content, unauthorized actions may be executed on the server as if they were the user. This security flaw could lead to a compromise of user actions and potentially affect confidentiality and integrity, while availability remains unaffected.

Affected Version(s)

SAP S/4HANA (Finance for Advanced Payment Management) S4CORE 105

SAP S/4HANA (Finance for Advanced Payment Management) 106

SAP S/4HANA (Finance for Advanced Payment Management) 107

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.