Executive brief
SAP S/4HANA's Manage Bank Chains application fails to properly validate user permissions when processing delete requests. A low-privileged user could bypass access controls to delete bank chain entries they should not be able to modify, disrupting critical banking operations and data integrity.
Technical details
This is an authorization bypass vulnerability (insufficient access control checks) in the Manage Bank Chains application module of SAP S/4HANA. The vulnerability exists in functionality that handles delete operations on specific business entities. An attacker with low-level privileges can craft specially-crafted requests that bypass authorization validation, allowing deletion of entries outside their permitted scope. The attack vector is network-based and does not require special user interaction or elevated privileges. Confidentiality and integrity are largely preserved, with impact limited to availability through unauthorized data deletion.
Affected products
- SAP S/4HANA <UNKNOWN>
Timeline
- 2026-09-08: disclosed