SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-44766

MEDIUM · CVSS 6.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

SAP S/4HANA's Intercompany Matching and Reconciliation component is vulnerable to input injection by low-privileged authenticated users, enabling them to send malicious data that may be executed by the database without adequate validation. This flaw poses a significant risk to the confidentiality of sensitive information, although it does not affect the integrity or availability of the application. Organizations using this SAP product should prioritize remediation to protect against potential data breaches.

CVE
CVE-2026-44766
Severity
MEDIUM
CVSS
6.5
EPSS
0.23%

Original NVD Description

SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access sensitive information, resulting in high impact on confidentiality, with no impact on integrity and availability of the application.