CVE-2026-66764: Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items)
Published Aug 11, 2026
·Updated
Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality, with no impact on integrity and availability of the application
Affected Software
1 affected component
SAP SAP S/4HANA - Reprocess Bank Statement Items
Event History
Aug 11, 2026
CVE Published
via MITRE·12:18 AM
Data Sourced
via MITRE·12:18 AM
DescriptionSeverity
Data Sourced
via NVD·01:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66764?
The severity of CVE-2026-66764 is medium with a score of 4.3.
2
How do I fix CVE-2026-66764?
To fix CVE-2026-66764, implement the latest security patch provided by SAP for S/4HANA.
3
What impact does CVE-2026-66764 have on confidentiality?
CVE-2026-66764 has a low impact on confidentiality.
4
What type of vulnerability is CVE-2026-66764?
CVE-2026-66764 is a missing authorization check vulnerability.
5
Who is affected by CVE-2026-66764?
Authenticated users of SAP S/4HANA who use the Reprocess Bank Statement Items feature are affected by CVE-2026-66764.