Description
SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.
Published: 2026-09-08
Score: 3.5 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP S/4HANA Finance for Advanced Payment Management allows attackers to craft malicious links or pages that can trigger unintended actions when an authenticated user visits them. The flaw stems from insufficient CSRF safeguards on certain requests, enabling the attacker to perform operations on the web server with the victim’s privileges. The resulting compromise affects confidentiality and integrity at a low level, with no impact on availability.

Affected Systems

SAP S/4HANA Finance (Advanced Payment Management) is affected. Specific version information is not provided in the CVE data, so all deployments of this product that implement the vulnerable functionality may be impacted.

Risk and Exploitability

The CVSS score of 3.5 indicates a low overall severity. EPSS information is not available, and the vulnerability is not listed in CISA KEV. An attacker with low privileges can exploit the flaw by hosting a malicious link or page that, when clicked by an authenticated user, triggers actions on the server. The exploitation requires the victim to be authenticated and to interact with the crafted content, and the impact remains modest, affecting only confidentiality and integrity without disrupting availability.

Generated by OpenCVE AI on September 8, 2026 at 01:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch referenced in SAP Note 3371336 to add CSRF protection to Finance for Advanced Payment Management.
  • Verify that all state‑changing endpoints require an anti‑CSRF token and that session cookies are marked HttpOnly and Secure.
  • Review exposed URLs and restrict sensitive actions to authorized roles, adding a confirmation step for critical operations where feasible.

Generated by OpenCVE AI on September 8, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.
Title Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-09-08T00:12:01.156Z

Reserved: 2026-08-20T05:15:36.823Z

Link: CVE-2026-76961

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T01:17:54.793

Modified: 2026-09-08T01:17:54.793

Link: CVE-2026-76961

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T01:30:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)