Cross-Site Request Forgery Vulnerability in SAP Fiori App
CVE-2026-0493
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 January 2026
What is CVE-2026-0493?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the SAP Fiori App Intercompany Balance Reconciliation, enabling an attacker to execute state-changing actions by manipulating the request type. This deviation from expected request semantics may allow unauthorized actions to be performed on behalf of authenticated users, potentially affecting the integrity of the system. However, it does not compromise the confidentiality or availability of the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP Fiori App (Intercompany Balance Reconciliation) UIAPFI70 500
SAP Fiori App (Intercompany Balance Reconciliation) 600
SAP Fiori App (Intercompany Balance Reconciliation) 700
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved