CVE-2026-0495: SAP SE SAP Fiori App Intercompany Balance Reconciliation

Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.

SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enable effective phishing campaigns. This has low impact on confidentiality, integrity and availability of the application.

Affected products

  • SAP SE SAP Fiori App Intercompany Balance Reconciliation: version 600 only; version 700 only; version 800 only; version 900 only; version 901 only; version 902 only; …

Published 2026-01-13. Last modified 2026-06-17.