CVE-2026-76974

MEDIUM CVSS 3.1: 5.3
Updated Sep 22, 2026
Sap_Se
Parameter Value
CVSS 5.3 (MEDIUM)
Type CWE-95
Vendor Sap_Se
Public PoC No

SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craft a malicious link that, when clicked by an authenticated user, causes the browser to load attacker-controlled content from an external location. This could be used to exfiltrate sensitive information from the victim's session, resulting in a high impact on confidentiality.

There is no impact on integrity and availability.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products

sap_se:sap fiori launchpad