AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66764

MEDIUM · CVSS 4.3 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability in SAP S/4HANA allows authenticated users to bypass necessary authorization checks when reprocessing bank statement items, potentially leading to privilege escalation through the use of unshared rules. While the impact on confidentiality is low and there is no effect on integrity or availability, organizations utilizing SAP S/4HANA should prioritize addressing this issue to prevent unauthorized access to sensitive functionalities.

CVE
CVE-2026-66764
Severity
MEDIUM
CVSS
4.3
EPSS
0.17%

Original NVD Description

Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality, with no impact on integrity and availability of the application