CVE-2026-76974
5.3 MEDIUMPublished 2026-09-22 · Updated 2026-09-22
AI risk analysis
- Summary
- The flaw allows unauthenticated attackers to craft a malicious link that can exfiltrate sensitive information from an authenticated user's session in SAP Fiori Launchpad.
- Exploitability
- Exploitation requires crafting and tricking an authenticated user into clicking a malicious link, making it moderately difficult.
- Blast radius
- If exploited, the impact is high as it could lead to significant data exfiltration from victims' sessions.
- Prioritized remediation
- Apply SAP's security patches for Fiori Launchpad to validate user input properly.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craft a malicious link that, when clicked by an authenticated user, causes the browser to load attacker-controlled content from an external location. This could be used to exfiltrate sensitive information from the victim's session, resulting in a high impact on confidentiality. There is no impact on integrity and availability.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Weaknesses
CWE-95
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-36468PoC
- LOWCVE-2026-94145PoC
- LOWCVE-2026-94426PoC
- CRITICALCVE-2025-29296
- MEDIUMCVE-2025-71419PoC
- MEDIUMCVE-2025-71420PoC
- HIGHCVE-2025-71421PoC
- CRITICALCVE-2026-10050PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.