CVE-2026-44766: SAP SE SAP s/4hana Intercompany Matching And Reconciliation
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access sensitive information, resulting in high impact on confidentiality, with no impact on integrity and availability of the application.
Affected products
- SAP SE SAP s/4hana Intercompany Matching And Reconciliation: version S4CORE 104 only; version 105 only; version 106 only; version 107 only; version 108 only; version 109 only
Published 2026-09-08. Last modified 2026-09-08.