CVE-2026-0496: SAP SE SAP Fiori App Intercompany Balance Reconciliation
Medium severity, CVSS 6.6. EPSS: 0.2% chance of exploitation in the next 30 days.
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including script files) without proper file format validation. This has low impact on confidentiality, integrity and availability of the application.
Affected products
- SAP SE SAP Fiori App Intercompany Balance Reconciliation: version 600 only; version 700 only; version 800 only; version 900 only; version 901 only; version 902 only; …
Published 2026-01-13. Last modified 2026-06-17.