VDB
CVE-2026-44770
CVE-2026-44770
PUBLISHED
CVSS 4.3 MEDIUM
Reported by sap · Published July 14, 2026
SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user could access specific entity set keys resulting in disclosure of information. This has low impact on confidentiality, with no impact on integrity and availability of the application.
Risk Scores
CVSS 3.1
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP_SE | SAP S/4 HANA (Create Single Payment) | S4CORE 102, 103, 104 |
| SAP_SE | SAP S/4 HANA (Create Single Payment) | S4CORE 102, 103, 104 |
Timeline
- Jul 14, 2026 EPSS Score
- Jul 14, 2026 Coalition ESS Score
- Jul 14, 2026 CVE Published
- Jul 14, 2026 CVE Updated