Skip to content
SAPCVE-2026-44770

SAP S/4 HANA (Create Single Payment): missing authorization

Medium4.3CVE-2026-44770 · Published Jul 14, 2026

SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user could access specific entity set keys resulting in disclosure of information. This has low impact on confidentiality, with no impact on integrity and availability of the application.

SAP advisory

Affected versions

PackageAffectedFixed in
SAP S/4 HANA (Create Single Payment)
Product
<= S4CORE 102No fix yet
<= 103No fix yet
<= 104No fix yet
<= 105No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-862

More SAP advisories

All SAP
Advisory
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented...
Critical9.1Jul 14
SAP @ui5/webcomponents-base: clickjacking
Medium6.1Jul 14
SAP CRM (WebClient UI): attacker could inject
Medium4.1Jul 14
SAP S/4HANA Project Management (PPM-PRO): SQL injection
Medium5.5Jul 14
SAP S/4HANA (Draft operation): privilege escalation
Medium4.3Jul 14
SAP Change and Transport System Attach Tool (ctsattach): unsafe deserialization
High7.6Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.