File Upload Vulnerability in SAP Fiori App by SAP
CVE-2026-0496
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 January 2026
What is CVE-2026-0496?
The SAP Fiori App Intercompany Balance Reconciliation has a critical flaw that allows an attacker with high privileges to upload files without adequate validation of their format. This vulnerability poses significant risks, as it could potentially enable the execution of harmful scripts or unauthorized access to sensitive information. Users are advised to apply necessary security patches to mitigate these risks effectively.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP Fiori App (Intercompany Balance Reconciliation) UIAPFI70 500
SAP Fiori App (Intercompany Balance Reconciliation) 600
SAP Fiori App (Intercompany Balance Reconciliation) 700
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved