Executive brief
SAP Fiori Launchpad, the central entry point for SAP business applications, is vulnerable to a security flaw where attackers can create deceptive web links. If a user clicks one of these links, the system may perform unauthorized actions or expose login credentials to the attacker. While this could lead to account compromise, the attack is difficult to execute and requires the attacker to have specific, advanced knowledge of the target system.
Technical details
A path traversal vulnerability (CWE-35) in SAP Fiori Launchpad allows remote attackers to craft malicious URLs that trigger arbitrary service calls within the Fiori domain. The vulnerability is exploited when a victim interacts with a specially crafted link, which can lead to the theft of user credentials or unauthorized service execution. Exploitation is considered difficult (High Attack Complexity) as it requires the adversary to possess advanced knowledge of the specific system environment. The impact is limited to low confidentiality and integrity loss, with no impact on system availability. SAP has addressed this in their June 2026 Security Patch Day.
Affected products
- SAP Fiori Launchpad
Timeline
- 2026-06-09: disclosed: Published as part of SAP Security Patch Day June 2026.
- 2026-06-09: advisory