CVE-2026-66764 PUBLISHED

Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items)

Assigner: sap
Reserved: 27.07.2026 Published: 11.08.2026 Updated: 11.08.2026

Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality, with no impact on integrity and availability of the application

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor SAP_SE
Product SAP S/4 HANA (Reprocess Bank Statement Items)
Versions Default: unaffected
  • Version S4CORE 104 is affected
  • Version 105 is affected
  • Version 106 is affected
  • Version 107 is affected
  • Version 108 is affected
  • Version 109 is affected

References

Problem Types