CVE-2026-24314: SAP s/4hana UIAPFI70
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which would otherwise be restricted. This could cause low impact on confidentiality of the application while integrity and availability are not impacted.
Affected products
- SAP s/4hana UIAPFI70: version 600 only; version 700 only; version 800 only; version 900 only; version 901 only; version 902 only
- SAP s/4hana UIS4H: version 109 only
Published 2026-02-24. Last modified 2026-06-17.