medium2026-08-11SAP FioriCVE-2026-66764

Missing Authorization Check in SAP Fiori Accounts Receivable Payment App

SAP Fiori for Finance (Accounts Receivable Payment)

Our Take

Missing auth on a payment Fiori app is a financial controls gap. SOX environments should treat this as a compliance item. Next planned window.

Vulnerability Detail

A missing authorisation check in the SAP Fiori Accounts Receivable Payment application allows an authenticated user to initiate or view payment transactions beyond their intended authorisation scope.

Patch Action

Apply SAP Note 3669608. Verify affected versions in the official SAP Note.

Patch Info

CVSS Score

4.3

SAP Note

3669608

CVE

CVE-2026-66764

Published

2026-08-11

← All patches