Junglewise Threat Intelligence

CVE-2026-44770: SAP S/4 HANA missing authorization check in Create Single Payment

CVE-2026-44770 · Severity: medium · CVSS 4.3 · Published 2026-07-14

Vendors: SAP SE.

Executive brief

SAP S/4 HANA, a business suite for managing enterprise operations, contains a flaw in its 'Create Single Payment' component. An authenticated user with restricted permissions can bypass authorization checks to view specific financial data they should not be able to access. While this allows for unauthorized information disclosure, it does not allow the user to modify data or disrupt the application's availability.

Technical details

A missing authorization check (CWE-862) exists in the SAP S/4 HANA 'Create Single Payment' component (S4CORE versions 102 through 109). An authenticated attacker with low privileges can exploit this vulnerability over the network to access specific entity set keys. This leads to unauthorized disclosure of information, though the impact is limited to confidentiality with no effect on data integrity or system availability. The vulnerability was addressed in the SAP July 2026 Security Patch Day.

Affected products

  • SAP SE SAP S/4 HANA (Create Single Payment) S4CORE 102, 103, 104, 105, 106, 107, 108, 109

Timeline

  • 2026-07-14: advisory: Initial publication by SAP and NVD

References