Input Validation Flaw in SAP Fiori Launchpad
CVE-2026-76974
5.3MEDIUM
What is CVE-2026-76974?
The SAP Fiori Launchpad has a vulnerability that stems from inadequate validation of user-controlled input. This flaw allows an unauthenticated attacker to exploit the system by crafting a malicious link that, once clicked by an authenticated user, prompts the browser to load content from an external source controlled by the attacker. Such an attack can lead to the unintended exposure of sensitive information from the user's session, thereby compromising the confidentiality of the data involved. Although there is no risk to integrity or availability, this type of vulnerability necessitates immediate attention to safeguard user data.
Affected Version(s)
SAP Fiori Launchpad SAP_UI 757
SAP Fiori Launchpad 758
SAP Fiori Launchpad 816