Junglewise Threat Intelligence

CVE-2026-76961: SAP S/4HANA Finance CSRF protection bypass in Advanced Payment Management

CVE-2026-76961 · Severity: low · CVSS 3.5 · Published 2026-09-08

Technologies: SAP S/4HANA Finance. Vendors: SAP.

Executive brief

SAP S/4HANA Finance's Advanced Payment Management module is missing proper Cross-Site Request Forgery (CSRF) protections on certain requests. An attacker with low privileges could trick an authenticated user into clicking a malicious link or visiting a crafted webpage, which would execute unintended payment or financial transactions on the victim's behalf. This could result in unauthorized financial actions, though the overall impact is limited to low-level confidentiality and integrity concerns with no availability impact.

Technical details

The vulnerability is a Cross-Site Request Forgery (CSRF) flaw in SAP S/4HANA Finance's Advanced Payment Management component, which fails to implement sufficient CSRF token validation on certain sensitive requests. The attack requires an authenticated user to be socially engineered into visiting a malicious page or clicking a malicious link while logged into the vulnerable system; no additional privilege escalation is needed beyond the attacker's existing low-level access. An attacker can craft requests that would be executed in the context of the victim's authenticated session, allowing them to perform unintended actions such as modifying payment data or initiating unauthorized transactions. The vulnerability has a reported CVSS score of 3.5 (low) and is not known to be actively exploited in the wild. A patch is available via SAP Security Note 3371336.

Affected products

  • SAP S/4HANA Finance <UNKNOWN>

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: SAP Security Note 3371336

References

Related threats