CVE-2026-76962 PUBLISHED

Missing Authorization check in SAP S/4HANA (Manage Bank Chains app)

Assigner: sap
Reserved: 20.08.2026 Published: 08.09.2026 Updated: 08.09.2026

SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no impact on confidentiality and integrity.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS Score: 4.3

Product Status

Vendor SAP_SE
Product SAP S/4HANA (Manage Bank Chains app)
Versions Default: unaffected
  • Version S4CORE 107 is affected
  • Version 108 is affected
  • Version 109 is affected

References

Problem Types