Path Traversal Vulnerability in SAP Fiori (launchpad)
CVE-2026-24315

4.2MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
9 June 2026

What is CVE-2026-24315?

SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on Confidentiality and Integrity. Availability of the system is no impacted.

Affected Version(s)

SAP Fiori (launchpad) SAP_UI 754

SAP Fiori (launchpad) 755

SAP Fiori (launchpad) 756

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.