CVE-2025-26660

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 11, 2025
CWE ID 639

Summary

CVE-2025-26660 is a vulnerability affecting SAP Fiori applications that use the posting library. During the setup process, these applications fail to adequately configure security settings, leaving them susceptible to unauthorized access. An attacker with low privileges can bypass access controls within the application, potentially enabling data modification. However, the vulnerability does not impact confidentiality or availability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share