medium2026-06-09SAP FioriCVE-2026-24315

Path Traversal in SAP Fiori Launchpad

SAP Fiori Launchpad

Our Take

The Fiori Launchpad is the face of modern SAP for end users — broadly deployed and regularly accessed. Path traversal is a lower-severity finding here, but the wide user base increases the attack surface. Include in your next Fiori update cycle.

Vulnerability Detail

A path traversal vulnerability in the SAP Fiori Launchpad allows an authenticated attacker to manipulate file path parameters to access resources outside the intended directory scope. Exploiting this flaw could expose configuration files or internal application data.

Patch Action

Apply SAP Note 3682699. Verify affected versions in the official SAP Note.

Patch Info

CVSS Score

4.2

SAP Note

3682699

CVE

CVE-2026-24315

Published

2026-06-09

← All patches