Description
SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.
Published: 2026-09-08
Score: 3.5 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A cross‑site request forgery flaw in SAP S/4HANA Finance (Advanced Payment Management) allows an attacker with low privileges to create a malicious link or page that, when visited by an authenticated user, triggers unintended state‑changing requests on the web server. The vulnerability does not compromise data confidentiality or system availability, but it may result in unauthorized or accidental changes to financial data, which is captured as a low‑severity confidentiality/integrity impact.

Affected Systems

The affected product is SAP S/4HANA Finance (Advanced Payment Management) from SAP SE. No specific version information is provided in the data, so all installations of this product should be considered potentially exposed until an update is applied.

Risk and Exploitability

The CVSS score of 3.5 reflects a low overall risk. EPSS information is currently unavailable, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is a web‑based request that requires a victim to be authenticated in the target system; thus the attack can be executed over the network by delivering a malicious link or page. If successful, the effect is limited to unauthorized, low‑gravity business actions rather than catastrophic data loss or downtime.

Generated by OpenCVE AI on September 8, 2026 at 01:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply SAP security note 3365276 to patch the CSRF validation flaw
  • Enable strict CSRF token validation for all state‑changing endpoints in the application
  • Configure cross‑origin request restrictions and appropriate security headers such as X‑Frame‑Options and Content‑Security‑Policy to reduce the attack surface

Generated by OpenCVE AI on September 8, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.
Title Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-09-08T00:11:51.253Z

Reserved: 2026-08-20T05:15:36.823Z

Link: CVE-2026-76960

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T01:17:54.680

Modified: 2026-09-08T01:17:54.680

Link: CVE-2026-76960

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T01:30:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)