Unrated severityNVD Advisory· Published Feb 24, 2026· Updated Feb 24, 2026
Information Disclosure vulnerability in S/4HANA (Manage Payment Media)
CVE-2026-24314
Description
Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which would otherwise be restricted. This could cause low impact on confidentiality of the application while integrity and availability are not impacted.
Affected products
2- SAP_SE/S/4HANA (Manage Payment Media)v5Range: UIAPFI70 600
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
7- Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation FlawsThe Hacker News · May 18, 2026
- Chipmaker Patch Tuesday: Intel and AMD Patch 70 VulnerabilitiesSecurityWeek · May 13, 2026
- Microsoft Patches 137 VulnerabilitiesSecurityWeek · May 12, 2026
- Adobe Patches 52 Vulnerabilities in 10 ProductsSecurityWeek · May 12, 2026
- SAP unveils Autonomous Enterprise for AI-driven business operationsHelp Net Security · May 12, 2026
- SAP Patches Critical S/4HANA, Commerce VulnerabilitiesSecurityWeek · May 12, 2026
- SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANABleepingComputer · May 12, 2026