216.73.217.22

CVE-2026-0496

· Published 13/01/2026 02:15 · Modified 13/01/2026 14:03

Labels: CVE-2026-0496 2026-01-13CVE-2026-0496CWE-434[email protected]

Essential information

Published
13/01/2026 02:15
Modified
13/01/2026 14:03
Author
Creator
CVSS
6.6 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

CVSS metrics

Description

SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including script files) without proper file format validation. This has low impact on confidentiality, integrity and availability of the application.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
sap / sap fiori cpe:2.3:a:sap:sap_fiori:*:*:*:*:*:*:*:*

References