CVE-2026-76959
Received Received - Intake

Cross-Site Request Forgery in SAP S/4HANA Finance

Vulnerability report for CVE-2026-76959, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: SAP SE

Description

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap s_4hana_finance *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Request Forgery (CSRF) issue in SAP S/4HANA Finance (Advanced Payment Management). It occurs because the application does not have sufficient CSRF protection on certain requests. An attacker with low privileges can create a malicious link or page that, when interacted with by an authenticated victim, triggers unintended actions on the web server on their behalf.

Impact Analysis

This vulnerability could allow an attacker to perform actions on the web server on behalf of an authenticated user without their consent. This may lead to unauthorized transactions or modifications, potentially affecting data integrity and confidentiality. However, the impact is considered low.

Compliance Impact

This vulnerability could potentially lead to unauthorized access or modifications of sensitive data, which may violate compliance requirements under GDPR or HIPAA. Organizations using SAP S/4HANA Finance should address this issue to maintain compliance with data protection regulations.

Mitigation Strategies

Apply SAP Security Note 3365311 as it addresses the insufficient CSRF protection in SAP S/4HANA Finance (Advanced Payment Management). Ensure all relevant patches are installed and review authentication mechanisms for web server interactions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76959. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart