medium2026-09-08SAP S/4HANA — Manage Bank ChainsCVE-2026-76962

Missing Authorization Check in Manage Bank Chains

SAP S/4HANA

Our Take

Bank master data exposure via a missing auth check. Lower severity but financial data has regulatory implications. Patch at next maintenance window and verify your F110/FBZP authorization assignments are clean.

Vulnerability Detail

Missing authorization check in the bank chain management application in SAP S/4HANA. An authenticated user could access bank chain data without the appropriate authorization object.

Patch Action

Apply the patch per SAP Note 3657599. Verify affected S/4HANA release in the official SAP Note.

Patch Info

CVSS Score

4.3

SAP Note

3657599

CVE

CVE-2026-76962

Published

2026-09-08

← All patches