---
id: CVE-2026-76959
title: >-
  SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient
  Cross-Site Request Forgery protection on certain requests due to this an
  attacker with low privileges could craft a malicious link or page
summary: >-
  SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient
  Cross-Site Request Forgery protection on certain requests due to this an
  attacker with low privileges could craft a malicious link or page. If an
  authenticated…
severity: medium
cvss: 4.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'
cwe:
  - CWE-352
vendor: SAP_SE
product: SAP S/4HANA (Finance for Advanced Payment Management)
affected:
  - sap_s_4hana_finance_for_advanced_payment_management UIAPFI70 800
  - sap_s_4hana_finance_for_advanced_payment_management 900
  - sap_s_4hana_finance_for_advanced_payment_management 901
  - sap_s_4hana_finance_for_advanced_payment_management 902
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:12:59.557'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76959'
references:
  - url: 'https://me.sap.com/notes/3365311'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
  - cve.org
epss: 0.00127
epssPercentile: 0.01995
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T10:01:21.935022Z'
ingestedAt: '2026-09-08T15:33:26.981Z'
---

## Overview

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
