CVE-2025-26660: SAP SE SAP Fiori Apps Posting Library
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an attacker with low privileges to bypass access controls within the application, enabling them to potentially modify data. Confidentiality and Availability are not impacted.
Affected products
- SAP SE SAP Fiori Apps Posting Library: version S4CORE 103 only; version 104 only; version 105 only; version 106 only; version 107 only; version 108 only
Published 2025-03-11. Last modified 2026-06-17.