Skip to content
SAPCVE-2026-76961

SAP S/4HANA: cross-site request forgery

Low3.5CVE-2026-76961 · Published Sep 8, 2026 · updated Sep 9, 2026

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.

SAP advisory

Affected versions

PackageAffectedFixed in
SAP S/4HANA (Finance for Advanced Payment Management)
Product
<= S4CORE 108No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-352

More SAP advisories

All SAP
Advisory
SAP NetWeaver and ABAP Platform: missing authorization
Medium4.3Sep 8
SAP NetWeaver Business Client: code execution
High7.8Sep 8
SAP Web Dispatcher, Internet: information disclosure
Medium6.5Sep 8
SAP Cloud Application Programming Model (CAP): weakly protected credentials
Critical9.4Sep 8
SAP Manufacturing Integration and Intelligence: server-side request forgery
Medium6.5Sep 8
SAP UI5 does not sufficiently validate the parent frame's origin against the...
Medium4.3Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.