CVE-2026-76962: SAP SE SAP s/4hana Manage Bank Chains App

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no impact on confidentiality and integrity.

Affected products

  • SAP SE SAP s/4hana Manage Bank Chains App: version S4CORE 107 only; version 108 only; version 109 only

Published 2026-09-08. Last modified 2026-09-08.