CVE-2026-76961
Received Received - Intake

Cross-Site Request Forgery in SAP S/4HANA Finance

Vulnerability report for CVE-2026-76961, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: SAP SE

Description

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap s_4hana_finance *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Request Forgery (CSRF) issue in SAP S/4HANA Finance (Advanced Payment Management). It occurs because the system does not have sufficient CSRF protection on certain requests. An attacker with low privileges can create a malicious link or page that, when interacted with by an authenticated user, triggers unintended actions on the web server on behalf of the victim. This results in low impact on confidentiality and integrity but does not affect availability.

Detection Guidance

Detecting this vulnerability requires checking for insufficient CSRF protection in SAP S/4HANA Finance (Advanced Payment Management). Review web server logs for suspicious requests or interactions with authenticated sessions. Use SAP tools to inspect request headers and session management for missing CSRF tokens.

Impact Analysis

An attacker could trick an authenticated user into clicking a malicious link or visiting a malicious page. This could cause the user to perform unintended actions on the SAP system, such as modifying financial data or triggering unauthorized transactions. The impact is limited to low confidentiality and integrity risks.

Compliance Impact

This vulnerability could potentially lead to unauthorized modifications of financial or sensitive data, which may violate compliance requirements under GDPR (data integrity) or HIPAA (unauthorized access or modification of protected health information). However, the low impact on confidentiality and integrity suggests minimal direct compliance risk.

Mitigation Strategies

Apply SAP security notes or patches referenced in SAP Note 3371336. Enable and enforce CSRF protection mechanisms in SAP S/4HANA Finance. Review and update web server configurations to ensure proper session validation and token checks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76961. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart