SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76962

MEDIUM · CVSS 4.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Manage Bank Chains app in SAP S/4HANA lacks adequate authorization checks, allowing attackers with low privileges to send crafted requests that can delete unauthorized entries. While the impact on availability is low, organizations using this application should prioritize remediation to prevent potential disruptions. SAP S/4HANA users, particularly those managing sensitive banking operations, should address this vulnerability promptly.

CVE
CVE-2026-76962
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%

Original NVD Description

SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no impact on confidentiality and integrity.