CVE-2026-40136 PUBLISHED

Denial of service (DoS) in SAP Financial Consolidation

Assigner: sap
Reserved: 09.04.2026 Published: 12.05.2026 Updated: 12.05.2026

SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions temporarily preventing access. However, the application itself cannot be compromised resulting in a low impact on availability. There is no impact on confidentiality and integrity of the data

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS Score: 4.3

Product Status

Vendor SAP_SE
Product SAP Financial Consolidation
Versions Default: unaffected
  • Version FINANCE 1010 is affected

References

Problem Types