Medium severity4.3NVD Advisory· Published Aug 11, 2026· Updated Aug 26, 2026
CVE-2026-66764
CVE-2026-66764
Description
Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality, with no impact on integrity and availability of the application
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
2- Critical SAP Vulnerabilities Let Attackers Inject Malicious Code and Corrupt MemoryCyber Security News · Aug 11, 2026
- SAP: 25 Vulnerabilities Disclosed, Critical Commerce Cloud Flaw Actively ExploitedVypr Intelligence · Aug 11, 2026