CVE-2026-76962
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Summary
SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no impact on confidentiality and integrity.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SAP_SE | SAP S/4HANA (Manage Bank Chains app) | S4CORE 107 | affected |
| SAP_SE | SAP S/4HANA (Manage Bank Chains app) | 108 | affected |
| SAP_SE | SAP S/4HANA (Manage Bank Chains app) | 109 | affected |
Weaknesses
- CWE-862: CWE-862: Missing Authorization
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.