Executive brief
SAP Fiori Launchpad, a portal application for accessing SAP business tools, fails to properly validate user input in links. An attacker can craft a malicious link that, when clicked by a logged-in user, forces the browser to load content from an attacker-controlled external site, enabling theft of sensitive session data and corporate information. This is a credential and data exfiltration risk affecting any organization using SAP Fiori.
Technical details
The vulnerability is an open redirect or cross-site scripting flaw in SAP Fiori Launchpad that fails to validate certain user-controlled input parameters, allowing an unauthenticated attacker to craft a malicious URL. When an authenticated user clicks the link, the browser loads attacker-controlled content, enabling session hijacking or sensitive data exfiltration. The attack requires user interaction (link click) but no authentication from the attacker.
Affected products
- SAP Fiori Launchpad
Timeline
- 2026-09-22: disclosed