SQL Injection vulnerability in SAP S/4HANA (Intercompany Matching and Reconciliation)
Summary
| CVE | CVE-2026-44766 |
|---|---|
| State | PUBLISHED |
| Assigner | sap |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-08 01:17:30 UTC |
| Updated | 2026-09-08 01:17:30 UTC |
| Description | SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access sensitive information, resulting in high impact on confidentiality, with no impact on integrity and availability of the application. |
Risk And Classification
Primary CVSS: v3.1 6.5 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Problem Types: CWE-89 | CWE-89 CWE-89: Improper Neutralization of Special Elements used in an SQL Command
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | SAP SE | SAP S/4HANA Intercompany Matching And Reconciliation | affected SAPSCORE 136 | Not specified |
| CNA | SAP SE | SAP S/4HANA Intercompany Matching And Reconciliation | affected S4CORE 104 | Not specified |
| CNA | SAP SE | SAP S/4HANA Intercompany Matching And Reconciliation | affected 105 | Not specified |
| CNA | SAP SE | SAP S/4HANA Intercompany Matching And Reconciliation | affected 106 | Not specified |
| CNA | SAP SE | SAP S/4HANA Intercompany Matching And Reconciliation | affected 107 | Not specified |
| CNA | SAP SE | SAP S/4HANA Intercompany Matching And Reconciliation | affected 108 | Not specified |
| CNA | SAP SE | SAP S/4HANA Intercompany Matching And Reconciliation | affected 109 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| url.sap/sapsecuritypatchday | [email protected] | url.sap | |
| me.sap.com/notes/3756450 | [email protected] | me.sap.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.