---
id: CVE-2026-76962
title: >-
  SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization
  checks within certain affected functionality
summary: >-
  SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization
  checks within certain affected functionality. An attacker with low privileges
  could send specially crafted requests to delete specific entries that should
  not…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-862
vendor: SAP_SE
product: SAP S/4HANA (Manage Bank Chains app)
affected:
  - sap_s_4hana_manage_bank_chains_app S4CORE 107
  - sap_s_4hana_manage_bank_chains_app 108
  - sap_s_4hana_manage_bank_chains_app 109
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:12:59.557'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76962'
references:
  - url: 'https://me.sap.com/notes/3657599'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
  - cve.org
epss: 0.00342
epssPercentile: 0.25063
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T10:04:05.462493Z'
ingestedAt: '2026-09-08T15:33:26.981Z'
---

## Overview

SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no impact on confidentiality and integrity.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
