Junglewise Threat Intelligence

CVE-2026-76960: SAP S/4HANA Finance Cross-Site Request Forgery in Advanced Payment Management

CVE-2026-76960 · Severity: low · CVSS 3.5 · Published 2026-09-08

Technologies: SAP S/4HANA Finance. Vendors: SAP.

Executive brief

SAP S/4HANA Finance's Advanced Payment Management module handles financial transactions and payment approvals. A weakness in CSRF protections allows an attacker to trick authenticated users into performing unintended actions (such as approving payments or modifying payment terms) by visiting a malicious link or page. This could result in unauthorized transactions or data tampering.

Technical details

The vulnerability is a Cross-Site Request Forgery (CSRF) flaw in SAP S/4HANA Finance's Advanced Payment Management module that lacks sufficient CSRF token validation on certain sensitive requests. An attacker with low privileges can craft a malicious link or webpage that, when visited by an authenticated victim, causes the victim's browser to perform unintended actions on the finance system. Attack preconditions include the victim being authenticated to S/4HANA and clicking a malicious link or visiting an attacker-controlled page. The impact is limited to low-severity confidentiality and integrity concerns; availability is not affected. Patches are available as SAP Security Notes per the regular Security Patch Day schedule.

Affected products

  • SAP S/4HANA Finance <UNKNOWN>

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: SAP Security Patch Day

References

Related threats