A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-24315

CVE-2026-24315: SAP Fiori Launchpad CSRF Vulnerability

CVE-2026-24315 is a Cross-Site Request Forgery flaw in SAP Fiori Launchpad enabling attackers to craft malicious URLs that steal user credentials. This article covers technical details, affected versions, and mitigation.

Published: June 11, 2026

CVE-2026-24315 Overview

CVE-2026-24315 affects the SAP Fiori Launchpad, where attackers can craft malicious URLs that trigger arbitrary service calls on the Fiori domain. When a user opens the crafted URL, the request executes in the context of the Fiori application and may expose credentials or session material to the attacker.

The flaw is categorized as a URL redirection and origin-trust weakness [CWE-35]. Exploitation requires user interaction and advanced knowledge of the target system, which limits scale but does not eliminate risk for high-value SAP environments.

Critical Impact

Successful exploitation can lead to account compromise through credential theft when a victim opens an attacker-crafted Fiori Launchpad URL.

Affected Products

  • SAP Fiori Launchpad (see SAP Note 3682699 for affected component versions)
  • SAP environments exposing the Fiori Launchpad to end users
  • SAP frontend deployments integrated with Fiori service endpoints

Discovery Timeline

  • 2026-06-09 - CVE-2026-24315 published to the National Vulnerability Database (NVD)
  • 2026-06-09 - SAP publishes SAP Note 3682699 as part of SAP Security Patch Day
  • 2026-06-09 - Last updated in NVD database

Technical Details for CVE-2026-24315

Vulnerability Analysis

The vulnerability resides in how the SAP Fiori Launchpad processes URL parameters that control downstream service invocations. An attacker constructs a URL pointing to the legitimate Fiori domain but embeds parameters that cause the Launchpad to issue arbitrary service calls when the victim opens the link.

Because the request originates from the trusted Fiori origin and runs within the authenticated user's session, the resulting service calls inherit user privileges. Attackers can chain this behavior to capture credentials, tokens, or sensitive responses tied to the authenticated session.

The Exploit Prediction Scoring System (EPSS) currently places this issue at a low likelihood of near-term exploitation, but targeted abuse remains plausible in environments where Fiori is internet-facing.

Root Cause

The root cause is insufficient validation of URL-supplied parameters that influence the destination and content of service calls made by the Fiori Launchpad. The Launchpad trusts attacker-controlled input to determine which service endpoint to invoke on its own domain, violating the principle of strict origin and target validation referenced in [CWE-35].

Attack Vector

The attack is network-based and requires user interaction. An attacker delivers the crafted URL through phishing, chat, or any channel where an authenticated SAP user may click it. Successful exploitation also requires advanced knowledge of the target SAP system, including valid service paths and parameter structures, which raises the attacker skill bar.

No verified public proof-of-concept code is available. Refer to the SAP Note 3682699 and the SAP Security Patch Day Update for vendor-supplied technical details.

Detection Methods for CVE-2026-24315

Indicators of Compromise

  • Unusual Fiori Launchpad URLs containing redirection parameters or service paths that reference non-standard endpoints.
  • Authenticated service calls to Fiori backends initiated immediately after a user clicks an external link.
  • Outbound HTTP traffic from Fiori service responses to attacker-controlled hosts shortly after user URL interaction.

Detection Strategies

  • Inspect web proxy and reverse proxy logs for Fiori Launchpad requests carrying suspicious query parameters or encoded URLs.
  • Correlate email or messaging gateway events with subsequent Fiori session activity to identify URL-driven exploitation chains.
  • Alert on authenticated SAP sessions that issue rapid sequences of unrelated service calls following a single inbound navigation event.

Monitoring Recommendations

  • Centralize SAP Fiori, web gateway, and identity provider logs in a SIEM for cross-source correlation.
  • Monitor for credential reuse from new IP addresses or user agents shortly after Fiori session activity.
  • Track changes to SAP authentication tokens and session cookies for anomalies tied to URL-based interactions.

How to Mitigate CVE-2026-24315

Immediate Actions Required

  • Apply the corrections described in SAP Note 3682699 to all affected SAP Fiori Launchpad systems.
  • Restrict external exposure of the Fiori Launchpad where business requirements allow, using VPN or zero-trust access controls.
  • Educate SAP users on phishing risks involving Fiori URLs and reinforce link-handling procedures.

Patch Information

SAP released the official fix on SAP Security Patch Day. Administrators should download and apply the corrections referenced in SAP Note 3682699 and review the consolidated SAP Security Patch Day Update for related notes and dependencies.

Workarounds

  • Enforce strict allowlists for Fiori Launchpad navigation targets at the reverse proxy or web dispatcher layer.
  • Apply Content Security Policy and Referrer-Policy headers to limit cross-origin behavior on the Fiori domain.
  • Require step-up authentication for sensitive Fiori services to reduce the value of any stolen session context.
bash
# Configuration example
# Example SAP Web Dispatcher rule to block suspicious Fiori Launchpad query parameters
# Adjust patterns to match your environment after testing in a non-production system
if %{QUERY_STRING} regimatch (sap-shell|sap-system|redirect|target)=.*(http|https)%3A
  RegRewriteResponse 403 "Blocked suspicious Fiori URL"
end

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeCSRF

  • Vendor/TechSap

  • SeverityMEDIUM

  • CVSS Score4.2

  • EPSS Probability0.03%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
  • Impact Assessment
  • ConfidentialityHigh
  • IntegrityLow
  • AvailabilityNone
  • CWE References
  • CWE-35
  • Technical References
  • SAP Note 3682699

  • SAP Security Patch Day Update
  • Related CVEs
  • CVE-2026-0493: SAP Fiori CSRF Vulnerability

  • CVE-2026-44750: SAP MDG Privilege Escalation Vulnerability

  • CVE-2026-44754: SAP ODP-RFC Information Disclosure Flaw

  • CVE-2026-44749: SAP Gateway Information Disclosure Flaw
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English