Cross-Site Request Forgery Vulnerability in SAP Fiori App
CVE-2026-0493
4.3MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 January 2026
What is CVE-2026-0493?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the SAP Fiori App Intercompany Balance Reconciliation, enabling an attacker to execute state-changing actions by manipulating the request type. This deviation from expected request semantics may allow unauthorized actions to be performed on behalf of authenticated users, potentially affecting the integrity of the system. However, it does not compromise the confidentiality or availability of the application.
Affected Version(s)
SAP Fiori App (Intercompany Balance Reconciliation) UIAPFI70 500
SAP Fiori App (Intercompany Balance Reconciliation) 600
SAP Fiori App (Intercompany Balance Reconciliation) 700