PT-2026-96322 · Sap · Sap Fiori Launchpad
CVE-2026-76974
·
Published
2026-09-22
·
Updated
2026-09-29
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Fiori Launchpad (affected versions not specified)
Description
SAP Fiori Launchpad fails to sufficiently validate certain user-controlled input. This allows an unauthenticated attacker to craft a malicious link that, if clicked by an authenticated user, forces the browser to load content from an external location controlled by the attacker. This mechanism can be used to exfiltrate sensitive information from the victim's session, leading to a high impact on confidentiality.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Fiori Launchpad