Junglewise Threat Intelligence

CVE-2026-66764: SAP S/4HANA authorization bypass in Bank Statement reprocessing

CVE-2026-66764 · Severity: medium · CVSS 4.3 · Published 2026-08-11

Technologies: SAP S/4HANA. Vendors: SAP.

Executive brief

SAP S/4HANA's Bank Statement reprocessing feature fails to enforce proper access controls, allowing authenticated users to access and apply bank reconciliation rules that should have been restricted to them. An attacker with legitimate system access can exploit this to use sensitive financial processing rules they shouldn't have permission to use, potentially manipulating bank statement processing and creating an audit trail inconsistent with assigned responsibilities.

Technical details

This is an authorization check bypass vulnerability in SAP S/4HANA's Bank Statement Item reprocessing component. The vulnerability affects the access control logic that should prevent authenticated users from using shared bank reconciliation rules outside their delegated permissions. The attack requires authentication and network access to the affected SAP system; no user interaction is needed beyond normal application use. An authenticated attacker can escalate privileges to use restricted financial rules, potentially manipulating bank statement processing without proper authorization controls. SAP has released a security patch as part of their regular patch day process.

Affected products

  • SAP S/4HANA

Timeline

  • 2026-08-11: disclosed

References

Related threats