medium2026-09-08SAP S/4HANA — Intercompany Matching and ReconciliationCVE-2026-44766

SQL Injection in Intercompany Matching and Reconciliation

SAP S/4HANA

Our Take

Authenticated SQL injection in a financial reconciliation module. Requires an already-authenticated user, limiting mass exploitation, but insider threat and compromised accounts are realistic vectors. S4CORE 104–109 spans a wide range of S/4HANA releases.

Vulnerability Detail

Malicious input injection allows access to sensitive information without proper validation in the Intercompany Matching and Reconciliation module. An authenticated attacker can craft SQL to read backend financial data.

Patch Action

Apply the patch per SAP Note 3756450 for S4CORE 104–109 or SAPSCORE 136 as applicable.

Affected Versions

S4CORE 104–109; SAPSCORE 136

Patch Info

CVSS Score

6.5

SAP Note

3756450

CVE

CVE-2026-44766

Published

2026-09-08

← All patches