CVE-2026-66764: SAP SE SAP s/4 Hana Reprocess Bank Statement Items

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality, with no impact on integrity and availability of the application

Affected products

  • SAP SE SAP s/4 Hana Reprocess Bank Statement Items: version S4CORE 104 only; version 105 only; version 106 only; version 107 only; version 108 only; version 109 only

Published 2026-08-11. Last modified 2026-08-26.