CVE-2026-44770: Missing Authorization check in SAP S/4 HANA (Create Single Payment)
SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user could access specific entity set keys resulting in disclosure of information. This has low impact on confidentiality, with no impact on integrity and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44770?
The severity of CVE-2026-44770 is medium, with a CVSS score of 4.3.
How do I fix CVE-2026-44770?
To address CVE-2026-44770, apply the latest security patches from SAP for S/4HANA that include the necessary authorization checks.
What are the potential impacts of CVE-2026-44770?
CVE-2026-44770 can lead to information disclosure for a restricted user without impacting the integrity and availability of the application.
What is the nature of the vulnerability in CVE-2026-44770?
CVE-2026-44770 is caused by missing authorization checks in the Create Single Payment function of SAP S/4HANA.
Who is affected by CVE-2026-44770?
Authenticated users with restricted access may be affected by CVE-2026-44770 due to improper authorization checks.