CVE-2026-44766
Received Received - Intake

SAP S/4HANA Intercompany Matching SQL Injection Vulnerability

Vulnerability report for CVE-2026-44766, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: SAP SE

Description

SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access sensitive information, resulting in high impact on confidentiality, with no impact on integrity and availability of the application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap s_4hana *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions. The database processes this input without proper validation, potentially leading to unauthorized access to sensitive information.

Detection Guidance

The provided CVE details do not include specific detection methods or commands. SAP recommends reviewing Security Note 3756450 for mitigation steps and detection guidance. Check SAP's security patch notes and apply relevant updates to address the vulnerability.

Impact Analysis

The impact includes high risk to confidentiality as sensitive data may be accessed by unauthorized users. Integrity and availability of the application remain unaffected. Attackers could exploit this to steal confidential business or customer information.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access to sensitive personal or health data. Organizations may face legal penalties, fines, and reputational damage for failing to protect such data adequately.

Mitigation Strategies

Apply the SAP Security Note referenced in SAP Note 3756450 to patch the vulnerability. Monitor SAP Security Notes and apply updates promptly. Restrict user privileges to minimize potential impact.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44766. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart