PT-2026-96322 · Sap · Sap Fiori Launchpad

CVE-2026-76974

·

Published

2026-09-22

·

Updated

2026-09-29

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Fiori Launchpad (affected versions not specified)
Description SAP Fiori Launchpad fails to sufficiently validate certain user-controlled input. This allows an unauthenticated attacker to craft a malicious link that, if clicked by an authenticated user, forces the browser to load content from an external location controlled by the attacker. This mechanism can be used to exfiltrate sensitive information from the victim's session, leading to a high impact on confidentiality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76974

Affected Products

Sap Fiori Launchpad