CVE-2026-76962

Summary

SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no impact on confidentiality and integrity.

Affected Software

VendorProductVersion RangeStatus
SAP_SESAP S/4HANA (Manage Bank Chains app)S4CORE 107affected
SAP_SESAP S/4HANA (Manage Bank Chains app)108affected
SAP_SESAP S/4HANA (Manage Bank Chains app)109affected

Weaknesses

  • CWE-862: CWE-862: Missing Authorization

References