{"id":"CVE-2026-76962","title":"SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality","summary":"SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-862"],"vendor":"SAP_SE","product":"SAP S/4HANA (Manage Bank Chains app)","affected":["sap_s_4hana_manage_bank_chains_app S4CORE 107","sap_s_4hana_manage_bank_chains_app 108","sap_s_4hana_manage_bank_chains_app 109"],"published":"2026-09-08","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:12:59.557","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76962","references":[{"url":"https://me.sap.com/notes/3657599","label":"cna@sap.com"},{"url":"https://url.sap/sapsecuritypatchday","label":"cna@sap.com"}],"tags":["nvd","cve.org"],"epss":0.00202,"epssPercentile":0.10441,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-08T10:04:05.462493Z"},"ingestedAt":"2026-09-08T15:33:26.981Z","slug":"CVE-2026-76962","body":"## Overview\n\nSAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no impact on confidentiality and integrity.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}