CVE-2025-26660
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Mar 11, 2025
CWE ID 639
Summary
CVE-2025-26660 is a vulnerability affecting SAP Fiori applications that use the posting library. During the setup process, these applications fail to adequately configure security settings, leaving them susceptible to unauthorized access. An attacker with low privileges can bypass access controls within the application, potentially enabling data modification. However, the vulnerability does not impact confidentiality or availability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.