File Upload Vulnerability in SAP Fiori App by SAP
CVE-2026-0496
6.6MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 January 2026
What is CVE-2026-0496?
The SAP Fiori App Intercompany Balance Reconciliation has a critical flaw that allows an attacker with high privileges to upload files without adequate validation of their format. This vulnerability poses significant risks, as it could potentially enable the execution of harmful scripts or unauthorized access to sensitive information. Users are advised to apply necessary security patches to mitigate these risks effectively.
Affected Version(s)
SAP Fiori App (Intercompany Balance Reconciliation) UIAPFI70 500
SAP Fiori App (Intercompany Balance Reconciliation) 600
SAP Fiori App (Intercompany Balance Reconciliation) 700