CVE-2026-66764EPSS p6.5%
CVE-2026-66764CVE-2026-66764
Description
Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality, with no impact on integrity and availability of the application
Scoring
| CVSS | 4.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 0.17% probability of exploitation · percentile 6.5% · 2026-08-11T12:00:17Z |
| Last modified | 2026-08-11 |