Answer in brief
CVE-2026-44766 records a Unknown severity vulnerability in SQL Injection vulnerability in SAP S/4HANA (Intercompany Matching and Reconciliation). The current sources do not mark it as known exploited. The current feed maps SAP_SE/SAP S/4HANA (Intercompany Matching and Reconciliation) (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps SAP_SE/SAP S/4HANA (Intercompany Matching and Reconciliation) (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| SAP_SE/SAP S/4HANA (Intercompany Matching and Reconciliation)generic | SAPSCORE 136 || S4CORE 104 || 105 || 106 || 107 || 108 || 109 | Not reported |
Published upstream
Sep 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 8, 2026
SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access sensitive information, resulting in high impact on confidentiality, with no impact on integrity and availability of the application.
Quoted source text, attributed separately from HOL analysis.