ZeroHour

CVE-2026-76959

niche

Cross-Site Request Forgery in SAP S/4HANA Finance Advanced Payment Management

CVSS 3.1
4.6 medium
EPSS
<1%p0
Published
()
Modified
AI analysis

SAP S/4HANA Finance (Advanced Payment Management) does not sufficiently protect certain requests against cross-site request forgery (CWE-352). An attacker with low privileges can craft a malicious link or web page, and when an authenticated user interacts with it, the browser issues requests that trigger unintended actions on the web server on the victim's behalf. Successful abuse yields a low impact on confidentiality and integrity, with no impact on availability. Any organization running the Advanced Payment Management component of SAP S/4HANA Finance is affected, with risk concentrated among finance and back-office users who browse other sites while authenticated to the application. There is no public proof-of-concept, no CISA KEV listing, and EPSS estimates only a 0.1% probability of exploitation within 30 days, so no exploitation is currently known.

What to do: Determine whether the Advanced Payment Management component is deployed in your SAP S/4HANA Finance landscape and apply the corresponding SAP security note from the September 2026 Patch Day release. Until patched, limit access to the application to necessary finance personnel and caution users about interacting with unsolicited links or pages while authenticated; no other workarounds are documented in the available data.

Affected
SAP S/4HANA Finance (Advanced Payment Management)
Estimated exposure
nichelikely hundreds to low thousands of enterprise deployments worldwide (exact count unknown) — SAP S/4HANA has a very large enterprise installed base, but Advanced Payment Management is a specialized finance subcomponent deployed by only a subset of customers, typically on internal networks rather than internet-facing systems, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.

Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

In the news

SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport

SAP's September 2026 Patch Day fixes 19 notes including CVE-2026-44756 (CVSS 10.0), unauthenticated memory corruption in SAP Extended Passport Processing kernels.

SAP shipped 19 new security notes plus one update across NetWeaver, S/4HANA, Integration Suite, Commerce Cloud, and Cloud Application Programming Model. Top issues include CVE-2026-44756 (CVSS 10.0 memory corruption in SAP Extended Passport Processing across many KERNEL and Web Dispatcher versions), CVE-2026-58240 (CVSS 9.8 missing authentication in NetWeaver Message Server), CVE-2026-76969 (CVSS 9.4 credential disclosure in CAP library sap/cds-mtxs), and CVE-2026-66768 (CVSS 9.0 access control flaw in SAP GUI for Java). No exploitation is reported; organizations running affected kernels are urged to patch urgently.