medium2026-09-08SAP S/4HANA — Intercompany Matching and ReconciliationCVE-2026-44766
SQL Injection in Intercompany Matching and Reconciliation
SAP S/4HANA
Our Take
Authenticated SQL injection in a financial reconciliation module. Requires an already-authenticated user, limiting mass exploitation, but insider threat and compromised accounts are realistic vectors. S4CORE 104–109 spans a wide range of S/4HANA releases.
Vulnerability Detail
Malicious input injection allows access to sensitive information without proper validation in the Intercompany Matching and Reconciliation module. An authenticated attacker can craft SQL to read backend financial data.
Patch Action
Apply the patch per SAP Note 3756450 for S4CORE 104–109 or SAPSCORE 136 as applicable.
Affected Versions
S4CORE 104–109; SAPSCORE 136
Patch Info