Missing Authorization Check in SAP S/4HANA Manage Bank Chains App Enables Entry Deletion
AI analysis
CVE-2026-76962 is a missing authorization check (CWE-862) in the Manage Bank Chains app of SAP S/4HANA. An authenticated attacker with low privileges can send specially crafted requests that delete specific entries they should not be permitted to access. The impact is limited to a low availability loss from these deletions, with no confidentiality or integrity impact. Only organizations running SAP S/4HANA with the Manage Bank Chains (bank chain management) functionality in use are affected. There is no known public proof-of-concept, the flaw is not listed in CISA KEV, and EPSS puts 30-day exploitation probability at roughly 0.2%, so no exploitation is currently known.
What to do: Apply the SAP security patch addressing CVE-2026-76962 from the September 2026 Security Patch Day; consult SAP's advisory for exact supported versions since affected ranges are not stated here. Until patched, review which low-privileged users have access to the Manage Bank Chains app and tighten or restrict their authorizations. Check application logs for unexpected deletion activity targeting bank chain entries to determine whether the issue has been triggered.
Affected
| SAP S/4HANA (Manage Bank Chains app) | — |
Estimated exposure
moderate≈1,000–10,000 enterprise instances running the affected app — SAP S/4HANA has thousands of enterprise customers worldwide, and only the subset operating the Manage Bank Chains (treasury/bank chain management) functionality with low-privileged app users is plausibly exposed, putting affected…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no impact on confidentiality and integrity.