CVE-2026-76959
Last modified
CVE-2026-76959 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. EPSS estimates a 0.09% chance of exploitation in the next 30 days.
Description
SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| SAP_SE | SAP S/4HANA (Finance for Advanced Payment Management) | UIAPFI70 800; 900; 901; 902 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-76959?
How severe is CVE-2026-76959?
How do I fix CVE-2026-76959?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-76945The affected Ebyte device relies on client-managed authentic…7.5
- CVE-2026-76949Authentication Bypass by Spoofing vulnerability in team-alem…9.1
- CVE-2026-7695A vulnerability has been found in Acrel Electrical EEMS Ente…7.3
- CVE-2026-76956In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation …7.5
- CVE-2026-76957libexpat before 2.8.4 lacks handler call depth tracking with…7.8
- CVE-2026-76958SAP Integration Suite does not sufficiently validate XML doc…8.5
- CVE-2026-7696A vulnerability was found in Acrel Electrical EEMS Enterpris…6.3
- CVE-2026-76960SAP S/4HANA Finance (Advanced Payment Management) does not p…3.5
- CVE-2026-76961SAP S/4HANA Finance (Advanced Payment Management) does not p…3.5
- CVE-2026-76962SAP S/4HANA (Manage Bank Chains app) does not perform suffic…4.3
- CVE-2026-76963Due to a missing authorization check in Application Server A…4.3
- CVE-2026-76967SAP NetWeaver Business Client does not perform sufficient va…7.8
Are you affected by CVE-2026-76959?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
