Path traversal - CVE-2026-24315
Published: July 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to read or modify files outside the intended directory.
The vulnerability exists due to path traversal in SAP Fiori launchpad when processing crafted path input. A remote attacker can trick the victim into using crafted content to read or modify files outside the intended directory.
User interaction is required.