Input Validation Flaw in SAP Fiori Launchpad
CVE-2026-76974

5.3MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
22 September 2026

What is CVE-2026-76974?

The SAP Fiori Launchpad has a vulnerability that stems from inadequate validation of user-controlled input. This flaw allows an unauthenticated attacker to exploit the system by crafting a malicious link that, once clicked by an authenticated user, prompts the browser to load content from an external source controlled by the attacker. Such an attack can lead to the unintended exposure of sensitive information from the user's session, thereby compromising the confidentiality of the data involved. Although there is no risk to integrity or availability, this type of vulnerability necessitates immediate attention to safeguard user data.

Affected Version(s)

SAP Fiori Launchpad SAP_UI 757

SAP Fiori Launchpad 758

SAP Fiori Launchpad 816

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.