CVE-2026-76960
Received Received - Intake

Cross-Site Request Forgery in SAP S/4HANA Finance

Vulnerability report for CVE-2026-76960, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: SAP SE

Description

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap s_4hana_finance *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Request Forgery (CSRF) issue in SAP S/4HANA Finance (Advanced Payment Management). It occurs because the application does not have sufficient CSRF protection on certain requests. An attacker with low privileges can create a malicious link or page. When an authenticated user interacts with it, unintended actions may be performed on the web server on their behalf.

Detection Guidance

This vulnerability involves insufficient CSRF protection in SAP S/4HANA Finance. Detection requires checking for missing or weak CSRF tokens in web requests. Inspect HTTP headers and form submissions for tokens in SAP web interfaces. Use tools like Burp Suite or OWASP ZAP to analyze traffic for predictable or missing CSRF tokens.

Impact Analysis

If you are an authenticated user of SAP S/4HANA Finance, an attacker could trick you into clicking a malicious link or visiting a malicious page. This could cause unintended actions to be executed on the server with your permissions, potentially leading to unauthorized transactions or data changes. The impact on confidentiality and integrity is low.

Compliance Impact

This vulnerability could potentially lead to unauthorized data modifications or transactions, which may violate compliance requirements under GDPR (data integrity) or HIPAA (unauthorized access or changes to financial or health data). Organizations using this SAP module should address it to maintain compliance.

Mitigation Strategies

Apply SAP Security Note 3365276 as soon as possible to patch the Cross-Site Request Forgery vulnerability in SAP S/4HANA Finance (Advanced Payment Management).

Review and enforce CSRF tokens for authenticated sessions in the affected application to prevent unauthorized actions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76960. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart