CVE-2025-26660
Last modified
CVE-2025-26660 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an attacker with low privileges to bypass access controls within the application, enabling them to potentially modify data. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an attacker with low privileges to bypass access controls within the application, enabling them to potentially modify data. Confidentiality and Availability are not impacted.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-26660?
How severe is CVE-2025-26660?
How do I fix CVE-2025-26660?
Are you affected by CVE-2025-26660?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
