Junglewise Threat Intelligence

CVE-2026-44766: SAP S/4HANA SQL injection in Intercompany Matching and Reconciliation

CVE-2026-44766 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: SAP S/4HANA. Vendors: SAP.

Executive brief

SAP S/4HANA's Intercompany Matching and Reconciliation module processes financial data between related companies. A low-privileged user can inject malicious SQL commands through unvalidated input fields, allowing unauthorized access to sensitive financial and customer data. This compromises data confidentiality without affecting system availability or data integrity.

Technical details

The vulnerability is a SQL injection flaw in the Intercompany Matching and Reconciliation component of SAP S/4HANA. User-supplied input is concatenated into database queries without proper parameterization or validation before execution. An authenticated user with low privilege level can craft malicious SQL statements to bypass intended access controls and retrieve sensitive information directly from the database. The attack requires authentication but no elevated privileges, and successful exploitation allows data exfiltration. Patches are available through SAP Security Notes (note 3756450).

Affected products

  • SAP S/4HANA <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats