What is CVE-2026-66764?
The "Reprocess Bank Statement Items" function in SAP S/4HANA lacks proper authorization checks, allowing authenticated users to use rules not shared with them, leading to privilege escalation. This vulnerability has a low impact on confidentiality and no impact on integrity or availability. Users should apply the security patches provided by SAP.
Azərbaycanca: SAP S/4HANA-da "Reprocess Bank Statement Items" funksiyasında avtorizasiya yoxlanışı aparılmır, bu da autentifikasiya olunmuş istifadəçilərə onlarla paylaşılmayan qaydalardan istifadə edərək imtiyazlarını yüksəltməyə imkan verir. Bu zəiflik məxfiliyə aşağı səviyyədə təsir göstərir, bütövlük və əlçatanlığa təsir etmir. İstifadəçilər SAP tərəfindən təqdim olunan təhlükəsizlik yamalarını tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: SAP
FAQ2
Which function in SAP S/4HANA is affected by CVE-2026-66764?
The vulnerability occurs in the "Reprocess Bank Statement Items" function due to a lack of proper authorization checks.
Is authentication required to exploit CVE-2026-66764?
Yes, the vulnerability allows authenticated users to escalate privileges by using rules not shared with them.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.