Advisory
A note with CVSS 4.2 for component CA-FLP-FE-COR was released by SAP on 09.06.2026. The correction/advisory 3682699 was described with "3682699 - [CVE-2026-24315] Path Traversal Vulnerability in SAP Fiori (launchpad)" and affects the system type SAP Fiori.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is path traversal within SAP Fiori.
Risk specification
SAP Fiori Launchpad allows an unauthenticated attacker to craft malicious URLs that trigger arbitrary service calls on the Fiori domain and, when accessed by a victim, result in unauthorized access to account credentials and unauthorized data modification.
Solution
The Fiori Launchpad has been enhanced to validate incoming URLs and block path traversal exploits.
The advisory is valid for
- SAP_UI 754 29
- SAP_UI 755 25
- SAP_UI 756 19
- SAP_UI 757 11
- SAP_UI 758 8
- SAP_UI 816 2
