Description
Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality, with no impact on integrity and availability of the application
Published: 2026-08-11
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the Reprocess Bank Statement Items function of SAP S/4 HANA, where an authenticated user fails to trigger the required authorization checks. As a result, users may apply processing rules that have never been shared with them, which allows them to elevate their privileges within the application. The impact on confidentiality is low, and there is no observable effect on the application's integrity or availability.

Affected Systems

SAP S/4 HANA instances that expose the Reprocess Bank Statement Items feature are impacted, specifically services provided by SAP SE under the product name SAP S/4 HANA (Reprocess Bank Statement Items). No version range was supplied in the CNA data, so the vulnerability may affect any deployed instance that has not applied the relevant SAP note 3669608.

Risk and Exploitability

With a CVSS score of 4.3 the vulnerability presents a moderate risk profile. The EPSS score is not available, and it is not included in CISA’s KEV catalog, suggesting limited public exploitation data. The likely attack path requires a legitimate user who has permission to invoke the reprocess function; the vulnerability is therefore exploitable in a privileged context rather than remotely. The lack of authorization checks means that any authorized user can increase their privileges by leveraging unapproved rules, but the impact does not extend beyond the application’s own data space. The overall threat is considered moderate, with a realistic but not imminent exploitation risk.

Generated by OpenCVE AI on August 11, 2026 at 01:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review current role assignments for users who can invoke Reprocess Bank Statement Items and remove any permissions that are not explicitly authorized.
  • Restrict the function to a minimal set of trusted users or disable it entirely for all but essential personnel until a patch is applied.
  • Apply the latest security patches or SAP Note 3669608 that address the missing authorization logic; if no patch is available, configure additional manual checks or audit logging to detect unauthorized rule usage.

Generated by OpenCVE AI on August 11, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality, with no impact on integrity and availability of the application
Title Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items)
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T00:18:00.279Z

Reserved: 2026-07-27T17:33:40.733Z

Link: CVE-2026-66764

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T01:30:04Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key