Junglewise Threat Intelligence

CVE-2026-76959: SAP S/4HANA Finance Advanced Payment Management CSRF protection bypass

CVE-2026-76959 · Severity: medium · CVSS 4.6 · Published 2026-09-08

Technologies: SAP S/4HANA Finance. Vendors: SAP.

Executive brief

SAP S/4HANA Finance's Advanced Payment Management module lacks sufficient CSRF protection on certain requests, allowing an attacker to craft a malicious webpage or link that, when clicked by an authenticated user, could perform unwanted financial transactions or configuration changes. This vulnerability affects the integrity and confidentiality of payment processing systems used in enterprise finance operations.

Technical details

This is a Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA Finance's Advanced Payment Management component. The vulnerability stems from insufficient CSRF token validation on certain HTTP requests, allowing an unauthenticated attacker to craft a malicious link or page that triggers unintended actions when an authenticated victim interacts with it. The attack requires victim interaction (clicking a malicious link while authenticated to the target system) but does not require elevated privileges. An attacker can cause unauthorized state-changing operations in the payment management system, including potential unauthorized payments or configuration modifications. A patch is available through SAP Security Note 3365311.

Affected products

  • SAP S/4HANA Finance <UNKNOWN>

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory: Published as part of SAP Security Patch Day

References

Related threats