CVE-2026-76960

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-08 01:17

Updated : 2026-09-08 19:12


NVD link : CVE-2026-76960

Mitre link : CVE-2026-76960

CVE.ORG link : CVE-2026-76960


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)