CVE-2026-66764

Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality, with no impact on integrity and availability of the application
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-11 01:17

Updated : 2026-08-26 19:00


NVD link : CVE-2026-66764

Mitre link : CVE-2026-66764

CVE.ORG link : CVE-2026-66764


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key