medium2026-08-11SAP FioriCVE-2026-66764
Missing Authorization Check in SAP Fiori Accounts Receivable Payment App
SAP Fiori for Finance (Accounts Receivable Payment)
Our Take
Missing auth on a payment Fiori app is a financial controls gap. SOX environments should treat this as a compliance item. Next planned window.
Vulnerability Detail
A missing authorisation check in the SAP Fiori Accounts Receivable Payment application allows an authenticated user to initiate or view payment transactions beyond their intended authorisation scope.
Patch Action
Apply SAP Note 3669608. Verify affected versions in the official SAP Note.
Patch Info