CVE-2026-44766 PUBLISHED

SQL Injection vulnerability in SAP S/4HANA (Intercompany Matching and Reconciliation)

Assigner: sap
Reserved: 07.05.2026 Published: 08.09.2026 Updated: 08.09.2026

SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access sensitive information, resulting in high impact on confidentiality, with no impact on integrity and availability of the application.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor SAP_SE
Product SAP S/4HANA (Intercompany Matching and Reconciliation)
Versions Default: unaffected
  • Version SAPSCORE 136 is affected
  • Version S4CORE 104 is affected
  • Version 105 is affected
  • Version 106 is affected
  • Version 107 is affected
  • Version 108 is affected
  • Version 109 is affected

References

Problem Types