SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on Confidentiality and Integrity. Availability of the system is no impacted.

Project Subscriptions

Vendors Products
Fiori Launchpad Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 09 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap fiori Launchpad
Vendors & Products Sap
Sap fiori Launchpad

Tue, 09 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
Description SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on Confidentiality and Integrity. Availability of the system is no impacted.
Title Path Traversal Vulnerability in SAP Fiori (launchpad)
Weaknesses CWE-35
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-06-09T13:19:44.991Z

Reserved: 2026-01-21T22:15:25.361Z

Link: CVE-2026-24315

cve-icon Vulnrichment

Updated: 2026-06-09T13:19:41.113Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-09T01:16:45.740

Modified: 2026-06-09T02:08:28.150

Link: CVE-2026-24315

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T08:45:37Z

Weaknesses