CVE-2026-40136: Denial of service (DoS) in SAP Financial Consolidation
SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions temporarily preventing access. However, the application itself cannot be compromised resulting in a low impact on availability. There is no impact on confidentiality and integrity of the data
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40136?
CVE-2026-40136 has a low impact severity as it only affects availability by disconnecting users without compromising the application.
How do I fix CVE-2026-40136?
To mitigate CVE-2026-40136, ensure that you regularly apply security patches and monitor user sessions effectively.
Who is affected by CVE-2026-40136?
Authenticated users of SAP Financial Consolidation are affected by CVE-2026-40136 due to session termination issues.
Can CVE-2026-40136 be exploited remotely?
CVE-2026-40136 cannot be exploited remotely as it requires authenticated access to the SAP Financial Consolidation system.
What type of attack does CVE-2026-40136 represent?
CVE-2026-40136 represents a Denial of Service (DoS) attack, impacting user session availability.