Medium severity4.2NVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026
CVE-2026-24315
CVE-2026-24315
Description
SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on Confidentiality and Integrity. Availability of the system is no impacted.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
3- SAP Security Update July 2026 – Patch for Critical SAP NetWeaver Flaw that Enables Memory CorruptionCyber Security News · Jul 14, 2026
- SAP Security Patch Day – Critical Vulnerabilities in SAP NetWeaver PatchedCyber Security News · Jun 9, 2026
- SAP: Twelve Vulnerabilities Disclosed Together on June 9, 2026Vypr Intelligence · Jun 9, 2026