ZeroHour

CVE-2026-76962

moderate

Missing Authorization Check in SAP S/4HANA Manage Bank Chains App Enables Entry Deletion

CVSS 3.1
4.3 medium
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-76962 is a missing authorization check (CWE-862) in the Manage Bank Chains app of SAP S/4HANA. An authenticated attacker with low privileges can send specially crafted requests that delete specific entries they should not be permitted to access. The impact is limited to a low availability loss from these deletions, with no confidentiality or integrity impact. Only organizations running SAP S/4HANA with the Manage Bank Chains (bank chain management) functionality in use are affected. There is no known public proof-of-concept, the flaw is not listed in CISA KEV, and EPSS puts 30-day exploitation probability at roughly 0.2%, so no exploitation is currently known.

What to do: Apply the SAP security patch addressing CVE-2026-76962 from the September 2026 Security Patch Day; consult SAP's advisory for exact supported versions since affected ranges are not stated here. Until patched, review which low-privileged users have access to the Manage Bank Chains app and tighten or restrict their authorizations. Check application logs for unexpected deletion activity targeting bank chain entries to determine whether the issue has been triggered.

Affected
SAP S/4HANA (Manage Bank Chains app)
Estimated exposure
moderate≈1,000–10,000 enterprise instances running the affected app — SAP S/4HANA has thousands of enterprise customers worldwide, and only the subset operating the Manage Bank Chains (treasury/bank chain management) functionality with low-privileged app users is plausibly exposed, putting affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no impact on confidentiality and integrity.

Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

In the news

SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport

SAP's September 2026 Patch Day fixes 19 notes including CVE-2026-44756 (CVSS 10.0), unauthenticated memory corruption in SAP Extended Passport Processing kernels.

SAP shipped 19 new security notes plus one update across NetWeaver, S/4HANA, Integration Suite, Commerce Cloud, and Cloud Application Programming Model. Top issues include CVE-2026-44756 (CVSS 10.0 memory corruption in SAP Extended Passport Processing across many KERNEL and Web Dispatcher versions), CVE-2026-58240 (CVSS 9.8 missing authentication in NetWeaver Message Server), CVE-2026-76969 (CVSS 9.4 credential disclosure in CAP library sap/cds-mtxs), and CVE-2026-66768 (CVSS 9.0 access control flaw in SAP GUI for Java). No exploitation is reported; organizations running affected kernels are urged to patch urgently.