medium2026-09-08SAP S/4HANA — Advanced Payment ManagementCVE-2026-76959

Cross-Site Request Forgery in Advanced Payment Management (3 of 3)

SAP S/4HANA

Our Take

See note 3371336. Three CSRF findings in one payment app in one release. Whoever did the security review this cycle was thorough.

Vulnerability Detail

Third Cross-Site Request Forgery vulnerability in SAP S/4HANA Advanced Payment Management. Third distinct endpoint found unprotected against CSRF in this release cycle.

Patch Action

Apply SAP Note 3365311 together with notes 3371336 and 3365276. Verify affected S/4HANA release in the official SAP Note.

Patch Info

CVSS Score

4.3

SAP Note

3365311

CVE

CVE-2026-76959

Published

2026-09-08

← All patches