Junglewise Threat Intelligence

CVE-2026-76974: SAP Fiori Launchpad input validation bypass

CVE-2026-76974 · Severity: medium · CVSS 5.3 · Published 2026-09-22

Vendors: SAP.

Executive brief

SAP Fiori Launchpad, a portal application for accessing SAP business tools, fails to properly validate user input in links. An attacker can craft a malicious link that, when clicked by a logged-in user, forces the browser to load content from an attacker-controlled external site, enabling theft of sensitive session data and corporate information. This is a credential and data exfiltration risk affecting any organization using SAP Fiori.

Technical details

The vulnerability is an open redirect or cross-site scripting flaw in SAP Fiori Launchpad that fails to validate certain user-controlled input parameters, allowing an unauthenticated attacker to craft a malicious URL. When an authenticated user clicks the link, the browser loads attacker-controlled content, enabling session hijacking or sensitive data exfiltration. The attack requires user interaction (link click) but no authentication from the attacker.

Affected products

  • SAP Fiori Launchpad

Timeline

  • 2026-09-22: disclosed

References

Related threats