ZeroHour

CVE-2026-76961

niche

CSRF vulnerability in SAP S/4HANA Finance (Advanced Payment Management)

CVSS 3.1
3.5 low
EPSS
<1%p1
Published
()
Modified
AI analysis

SAP S/4HANA Finance (Advanced Payment Management) fails to apply sufficient Cross-Site Request Forgery (CSRF, CWE-352) protection to certain requests in its web interface. An attacker who already holds low-privileged access can craft a malicious link or page, and when an authenticated victim interacts with it, unintended actions are executed on the web server on the victim's behalf. The result is a low impact on confidentiality and integrity with no impact on availability; CVSS 3.1 scores it 3.5 (Low). Only organizations running the Advanced Payment Management component of SAP S/4HANA Finance are affected. As of the advisory, there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, EPSS assigns roughly a 0.1% probability of exploitation within 30 days, and a fix was shipped as part of SAP's September 2026 security update.

What to do: Apply the security note released in SAP's September 2026 Patch Day for S/4HANA Finance (Advanced Payment Management) and verify the patched support package level against the official SAP advisory, since affected version ranges were not included in the data provided. Until patched, restrict the APM web interface to trusted internal networks and remind finance users not to follow unsolicited links while authenticated. No public exploit is known, so prompt patching and access restriction are sufficient.

Affected
SAP S/4HANA Finance (Advanced Payment Management)
Estimated exposure
nichelikely hundreds to a few thousand enterprise installations of the APM component (exact count unknown) — SAP S/4HANA runs at tens of thousands of customers, but Advanced Payment Management is a specialized finance add-on adopted by only a subset of large enterprises, and exploitation additionally requires the APM web UI to be reachable and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.

Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

In the news

SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport

SAP's September 2026 Patch Day fixes 19 notes including CVE-2026-44756 (CVSS 10.0), unauthenticated memory corruption in SAP Extended Passport Processing kernels.

SAP shipped 19 new security notes plus one update across NetWeaver, S/4HANA, Integration Suite, Commerce Cloud, and Cloud Application Programming Model. Top issues include CVE-2026-44756 (CVSS 10.0 memory corruption in SAP Extended Passport Processing across many KERNEL and Web Dispatcher versions), CVE-2026-58240 (CVSS 9.8 missing authentication in NetWeaver Message Server), CVE-2026-76969 (CVSS 9.4 credential disclosure in CAP library sap/cds-mtxs), and CVE-2026-66768 (CVSS 9.0 access control flaw in SAP GUI for Java). No exploitation is reported; organizations running affected kernels are urged to patch urgently.