CVE-2025-42876
Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authenticated attacker with authorization limited to a single company code could read sensitive data and post or modify documents across all company codes. Successful exploitation could result in a high impact to confidentiality and a low impact to integrity, while availability remains unaffected.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- EPSS probability
- 0.30%
- CWE
- CWE-405
- Published
- 2025-12-09
- Last modified
- 2026-03-13
Affected products
- SAP_SE SAP S/4 HANA Private Cloud (Financials General Ledger)
- SAP_SE SAP S/4 HANA Private Cloud (Financials General Ledger)
- SAP_SE SAP S/4 HANA Private Cloud (Financials General Ledger)
- SAP_SE SAP S/4 HANA Private Cloud (Financials General Ledger)
- SAP_SE SAP S/4 HANA Private Cloud (Financials General Ledger)
- SAP_SE SAP S/4 HANA Private Cloud (Financials General Ledger)
Weakness type
Related vulnerabilities
- CVE-2026-87011 — Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
- CVE-2026-86432 — commonmark 2.0.0 before 2.8.4 Denial of Service via XML
- CVE-2026-82309 — Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries
- CVE-2026-84310 — pypdf: Possible long runtimes/large memory usage when retrieving outlines
- CVE-2026-54874 — Excessive Memory Use Buffering DTLS Records for a Future Epoch
- CVE-2026-23934 — Frontend DoS via the validate.api.exists action
- CVE-2026-23930 — Frontend DoS via the popup.testtriggerexpr action
- CVE-2026-72914 — Mastodon: Exhausting data by an unauthenticated request to the admin retention API