ZeroHour

CVE-2026-76960

niche

Cross-Site Request Forgery in SAP S/4HANA Finance (Advanced Payment Management)

CVSS 3.1
3.5 low
EPSS
<1%p1
Published
()
Modified
AI analysis

SAP S/4HANA Finance (Advanced Payment Management) does not adequately enforce Cross-Site Request Forgery (CWE-352) protections on certain requests. An attacker with low privileges can craft a malicious link or page, and when an authenticated victim interacts with it, unintended actions are executed on the web server on the victim's behalf. The attacker gains the ability to induce integrity-affecting state changes through the victim's session, with low confidentiality impact and no availability impact per the advisory (CVSS 3.1 score 3.5). Any organization running the affected SAP S/4HANA Finance component is exposed, primarily through phishing or attacker-controlled pages rather than direct server access. There is no known public proof of concept, it is not in the CISA KEV catalog, and EPSS puts 30-day exploitation probability at about 0.1%; fixes were shipped as part of SAP's September 2026 security update release.

What to do: Apply the SAP security patch for this issue from the September 2026 SAP security update release after checking the SAP advisory for the exact corrected versions of the Advanced Payment Management component. Inventory which S/4HANA systems run this add-on and prioritize patching any that are web-exposed; until patched, caution users about clicking links or visiting untrusted pages while authenticated, and consider standard CSRF mitigations such as SameSite cookie handling on the gateway/frontend. No public exploit is known, so exploitation risk is currently low.

Affected
SAP S/4HANA Finance (Advanced Payment Management)
Estimated exposure
nichelikely a few thousand deployments at most — Advanced Payment Management is an optional finance add-on within SAP S/4HANA, deployed at only a subset of the roughly 20,000+ S/4HANA customer installations, and it is typically internal-facing rather than internet-exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.

Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

In the news

SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport

SAP's September 2026 Patch Day fixes 19 notes including CVE-2026-44756 (CVSS 10.0), unauthenticated memory corruption in SAP Extended Passport Processing kernels.

SAP shipped 19 new security notes plus one update across NetWeaver, S/4HANA, Integration Suite, Commerce Cloud, and Cloud Application Programming Model. Top issues include CVE-2026-44756 (CVSS 10.0 memory corruption in SAP Extended Passport Processing across many KERNEL and Web Dispatcher versions), CVE-2026-58240 (CVSS 9.8 missing authentication in NetWeaver Message Server), CVE-2026-76969 (CVSS 9.4 credential disclosure in CAP library sap/cds-mtxs), and CVE-2026-66768 (CVSS 9.0 access control flaw in SAP GUI for Java). No exploitation is reported; organizations running affected kernels are urged to patch urgently.