CVE-2026-24315
Awaiting Analysis Awaiting Analysis - Queue
SAP Fiori Launchpad URL-based Service Call Vulnerability

Publication date: 2026-06-09

Last updated on: 2026-06-09

Assigner: SAP SE

Description
SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on Confidentiality and Integrity. Availability of the system is no impacted.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-09
Last Modified
2026-06-09
Generated
2026-06-09
AI Q&A
2026-06-09
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
sap fiori_launchpad *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-35 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in SAP Fiori Launchpad and allows attackers to create malicious URLs that trigger arbitrary service calls within the Fiori domain.

When a user opens such a crafted URL, their account could be compromised by stealing user credentials.

Exploitation requires attackers to have advanced knowledge of the system.

Impact Analysis

The vulnerability can lead to compromise of user accounts through credential theft.

The impact on confidentiality and integrity is considered low.

There is no impact on the availability of the system.

Compliance Impact

This vulnerability in SAP Fiori Launchpad allows attackers to craft malicious URLs that can steal user credentials if opened by the user. Such unauthorized access to user credentials could potentially lead to data breaches involving personal or sensitive information.

Given that the vulnerability can compromise confidentiality and integrity of user accounts, it may impact compliance with standards and regulations like GDPR and HIPAA, which require protection of personal data and user privacy.

However, the impact is rated as low on confidentiality and integrity, and availability is not affected. Successful exploitation requires advanced knowledge and user interaction, which may mitigate the risk but does not eliminate compliance concerns.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-24315. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart