CVE-2026-40136

MEDIUM

Denial of service (DoS) in SAP Financial Consolidation

Title source: cna
STIX 2.1

Description

SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions temporarily preventing access. However, the application itself cannot be compromised resulting in a low impact on availability. There is no impact on confidentiality and integrity of the data

Scores

CVSS v3 4.3
EPSS 0.0001
EPSS Percentile 3.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (1)
SAP_SE/SAP Financial Consolidation FINANCE 1010
Published May 12, 2026
Tracked Since May 12, 2026