---
id: CVE-2026-44766
title: >-
  SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged
  authenticated user to inject malicious input into certain functions, which may
  be processed by the database without proper validation
summary: >-
  SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged
  authenticated user to inject malicious input into certain functions, which may
  be processed by the database without proper validation. This could allow the
  us…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-89
vendor: SAP_SE
product: SAP S/4HANA (Intercompany Matching and Reconciliation)
affected:
  - sap_s_4hana_intercompany_matching_and_reconciliation SAPSCORE 136
  - sap_s_4hana_intercompany_matching_and_reconciliation S4CORE 104
  - sap_s_4hana_intercompany_matching_and_reconciliation 105
  - sap_s_4hana_intercompany_matching_and_reconciliation 106
  - sap_s_4hana_intercompany_matching_and_reconciliation 107
  - sap_s_4hana_intercompany_matching_and_reconciliation 108
  - sap_s_4hana_intercompany_matching_and_reconciliation 109
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:12:59.557'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44766'
references:
  - url: 'https://me.sap.com/notes/3756450'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
  - cve.org
epss: 0.00386
epssPercentile: 0.29813
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T10:05:31.349235Z'
ingestedAt: '2026-09-08T15:33:26.981Z'
---

## Overview

SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access sensitive information, resulting in high impact on confidentiality, with no impact on integrity and availability of the application.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
