Access Control Flaw in SAP S/4HANA Manage Bank Chains Application
CVE-2026-76962

4.3MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
8 September 2026

What is CVE-2026-76962?

The SAP S/4HANA Manage Bank Chains application is affected by an authorization bypass vulnerability that allows an attacker with low privileges to execute specially crafted requests. This vulnerability permits unauthorized deletion of specific entries, which should not be accessible to such low-privilege users. While this impacts the availability of the application, it does not compromise the confidentiality or integrity of the system data.

Affected Version(s)

SAP S/4HANA (Manage Bank Chains app) S4CORE 107

SAP S/4HANA (Manage Bank Chains app) 108

SAP S/4HANA (Manage Bank Chains app) 109

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.