{"id":"CVE-2026-76974","published":"2026-09-22T01:16:53.837","lastModified":"2026-09-22T01:16:53.837","description":"SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craft a malicious link that, when clicked by an authenticated user, causes the browser to load attacker-controlled content from an external location. This could be used to exfiltrate sensitive information from the victim's session, resulting in a high impact on confidentiality. There is no impact on integrity and availability.","cvssScore":5.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","cwes":["CWE-95"],"vendors":[],"products":[],"references":[{"url":"https://me.sap.com/notes/3680888","tags":[]},{"url":"https://url.sap/sapsecuritypatchday","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated attackers to craft a malicious link that can exfiltrate sensitive information from an authenticated user's session in SAP Fiori Launchpad.","exploitability":"Exploitation requires crafting and tricking an authenticated user into clicking a malicious link, making it moderately difficult.","blast_radius":"If exploited, the impact is high as it could lead to significant data exfiltration from victims' sessions.","remediation":"Apply SAP's security patches for Fiori Launchpad to validate user input properly.","tags":["web","sensitive-data-exposure","input-validation"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:29:41.408Z"}}