---
id: CVE-2026-76974
title: >-
  SAP Fiori Launchpad does not sufficiently validate certain user-controlled
  input
summary: >-
  SAP Fiori Launchpad does not sufficiently validate certain user-controlled
  input. An unauthenticated attacker could craft a malicious link that, when
  clicked by an authenticated user, causes the browser to load
  attacker-controlled conten…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-95
vendor: SAP_SE
product: SAP Fiori Launchpad
affected:
  - sap_fiori_launchpad SAP_UI 757
  - sap_fiori_launchpad 758
  - sap_fiori_launchpad 816
  - sap_fiori_launchpad SAP_BASIS 918
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:37:36.747'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76974'
references:
  - url: 'https://me.sap.com/notes/3680888'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
  - cve.org
epss: 0.00349
epssPercentile: 0.25743
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-22T10:11:02.586099Z'
ingestedAt: '2026-09-22T00:55:54.017Z'
---

## Overview

SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craft a malicious link that, when clicked by an authenticated user, causes the browser to load attacker-controlled content from an external location. This could be used to exfiltrate sensitive information from the victim's session, resulting in a high impact on confidentiality. There is no impact on integrity and availability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
