CVE-2026-76962
- EPSS 0.2%
- Veröffentlicht 08.09.2026 01:17:54
- Zuletzt bearbeitet 08.09.2026 19:12:59
SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessibl...
CVE-2026-44766
- EPSS 0.23%
- Veröffentlicht 08.09.2026 01:17:30
- Zuletzt bearbeitet 08.09.2026 19:12:59
SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access ...
CVE-2026-66766
- EPSS 0.29%
- Veröffentlicht 25.08.2026 01:08:36
- Zuletzt bearbeitet 26.08.2026 19:00:14
SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affect...
CVE-2026-66764
- EPSS 0.17%
- Veröffentlicht 11.08.2026 00:18:00
- Zuletzt bearbeitet 26.08.2026 19:00:14
Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low ...
CVE-2026-44770
- EPSS 0.17%
- Veröffentlicht 14.07.2026 00:21:18
- Zuletzt bearbeitet 14.07.2026 16:46:49
SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user could access specific entity set keys resulting in disclosure of information. This has low impact on confidentiality, with no impac...
CVE-2026-44744
- EPSS 0.22%
- Veröffentlicht 09.06.2026 00:20:37
- Zuletzt bearbeitet 23.07.2026 08:10:00
SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be exploited by an authenticated attacker to potentially execute unauthorized database queries.This flaw exposes sensitive informati...
CVE-2026-27678
- EPSS 0.18%
- Veröffentlicht 14.04.2026 00:07:33
- Zuletzt bearbeitet 17.04.2026 15:18:16
Due to missing authorization checks in the SAP S/4HANA backend OData Service (Manage Reference Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability has a high impa...
CVE-2026-27677
- EPSS 0.18%
- Veröffentlicht 14.04.2026 00:07:22
- Zuletzt bearbeitet 17.04.2026 15:18:16
Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment), an attacker could update and delete child entities via OData services without proper authorization. This vulnerability has a high impact on integrity, ...
CVE-2026-27673
- EPSS 0.16%
- Veröffentlicht 14.04.2026 00:06:38
- Zuletzt bearbeitet 17.04.2026 15:18:16
Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete files on the operating system and gain unauthorized control over file operations which could leads to no impact on Confidentiality...
CVE-2026-24314
- EPSS 0.2%
- Veröffentlicht 24.02.2026 05:23:52
- Zuletzt bearbeitet 03.03.2026 00:28:43
Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which would otherwise be restricted. This could cause low impact on confidentiality of the application while integrity and availability...