CVE-2025-42991
Description
SAP S/4HANA Bank Account Application lacks authorization checks, allowing an authenticated approver to delete other users' attachments, with low integrity impact.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
SAP S/4HANA Bank Account Application lacks authorization checks, allowing an authenticated approver to delete other users' attachments, with low integrity impact.
The vulnerability resides in SAP S/4HANA's Bank Account Application component. Due to missing authorization checks, the application fails to verify that an authenticated user with the 'approver' role has the proper permissions to delete attachments belonging to other users. This is an authorization bypass issue.
An attacker who is an authenticated user with the 'approver' role can exploit this by sending a crafted request to delete an attachment from a bank account application that belongs to another user. No special network position is required beyond normal authenticated access. The attack does not require any additional privileges beyond the 'approver' role.
Successful exploitation allows the attacker to delete attachments of other users, leading to a low impact on integrity. The confidentiality and availability of the application are not affected. The deleted attachments could be important documents related to bank account applications.
SAP has released a security note as part of its monthly Security Patch Day to address this vulnerability [1]. Users are advised to apply the relevant patch as soon as possible. No workarounds are mentioned. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog as of publication.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.