Junglewise Threat Intelligence

CVE-2026-40136: SAP Financial Consolidation session termination vulnerability

CVE-2026-40136 · Severity: medium · CVSS 4.3 · Published 2026-05-12

Vendors: SAP.

Executive brief

SAP Financial Consolidation, a tool used by organizations for financial reporting and closing, is affected by a vulnerability that allows an authorized user to disrupt the work of others. An attacker can forcibly terminate the active sessions of other users, temporarily preventing them from accessing the system. While this does not lead to data theft or permanent system damage, it can cause operational delays during critical financial periods.

Technical details

A vulnerability classified as Improper Resource Shutdown or Release (CWE-404) exists in SAP Financial Consolidation. An authenticated attacker with low privileges can exploit this flaw over the network to terminate the sessions of other concurrent users. This results in a partial loss of availability as legitimate users are disconnected and must re-authenticate to regain access. The vulnerability does not allow for unauthorized data access (confidentiality) or data modification (integrity). SAP has released Security Note 3713521 to address this issue.

Affected products

  • SAP Financial Consolidation

Timeline

  • 2026-05-12: advisory: SAP published security note 3713521 during May 2026 Patch Day
  • 2026-05-12: disclosed: NVD published the CVE record

References