← Back to search

CVE-2026-76974

5.3 MEDIUM

Published 2026-09-22 · Updated 2026-09-22

AI risk analysis

Summary
The flaw allows unauthenticated attackers to craft a malicious link that can exfiltrate sensitive information from an authenticated user's session in SAP Fiori Launchpad.
Exploitability
Exploitation requires crafting and tricking an authenticated user into clicking a malicious link, making it moderately difficult.
Blast radius
If exploited, the impact is high as it could lead to significant data exfiltration from victims' sessions.
Prioritized remediation
Apply SAP's security patches for Fiori Launchpad to validate user input properly.
websensitive-data-exposureinput-validation

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craft a malicious link that, when clicked by an authenticated user, causes the browser to load attacker-controlled content from an external location. This could be used to exfiltrate sensitive information from the victim's session, resulting in a high impact on confidentiality. There is no impact on integrity and availability.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Weaknesses

CWE-95

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.