CVE-2026-76974

Summary

SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craft a malicious link that, when clicked by an authenticated user, causes the browser to load attacker-controlled content from an external location. This could be used to exfiltrate sensitive information from the victim's session, resulting in a high impact on confidentiality. There is no impact on integrity and availability.

Affected Software

VendorProductVersion RangeStatus
SAP_SESAP Fiori LaunchpadSAP_UI 757affected
SAP_SESAP Fiori Launchpad758affected
SAP_SESAP Fiori Launchpad816affected
SAP_SESAP Fiori LaunchpadSAP_BASIS 918affected

Weaknesses

  • CWE-95: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code

References