CVE-2026-76960

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.

Scoring

Severity
LOW
CVSS base score
3.5
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
EPSS probability
0.09%
CWE
CWE-352
Published
2026-09-08
Last modified
2026-09-08

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs