---
id: CVE-2025-42876
title: >-
  Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private
  Cloud (Financials General Ledger), an authenticated attacker with
  authorization limited to a single company code could read sensitive data and
  post or modify docu…
summary: >-
  Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private
  Cloud (Financials General Ledger), an authenticated attacker with
  authorization limited to a single company code could read sensitive data and
  post or modify docu…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-405
published: '2025-12-09'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-42876'
references:
  - url: 'https://me.sap.com/notes/3672151'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
epss: 0.00303
epssPercentile: 0.2104
ingestedAt: '2026-10-07T20:46:46.794Z'
---

## Overview

Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authenticated attacker with authorization limited to a single company code could read sensitive data and post or modify documents across all company codes. Successful exploitation could result in a high impact to confidentiality and a low impact to integrity, while availability remains unaffected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
