CVE-2026-0495
published 2026-01-13CVE-2026-0495: SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enable…
PriorityP427medium5.1CVSS 3.1
AVNACHPRHUIRSCCLILAL
EPSS
0.15%
4.6th percentile
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enable effective phishing campaigns. This has low impact on confidentiality, integrity and availability of the application.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
CVSS provenance
nvdv3.15.1MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5429-v87q-pg8h: SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enabl
ghsa_unreviewed·2026-01-13
CVE-2026-0495 [MEDIUM] CWE-15 GHSA-5429-v87q-pg8h: SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enabl
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enable effective phishing campaigns. This has low impact on confidentiality, integrity and availability of the application.
Red Hat
vim: Vim: Arbitrary Code Execution via crafted directory names
vendor_redhat·2026-06-11·CVSS 8.8
CVE-2026-47162 [HIGH] CWE-140 vim: Vim: Arbitrary Code Execution via crafted directory names
vim: Vim: Arbitrary Code Execution via crafted directory names
Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name derived from the filesystem is interpolated into a single-quoted Vimscript string literal without escaping embedded single quotes, allowing a crafted directory name to break out of the string context and execute arbitrary Vimscript, including shell commands via system() and :!, the next time the history file is sourced. This issue has been patched in version 9.2.0495.
A flaw was found in Vim, an open-source text edit
No detection rules found.
No public exploits indexed.
2026-01-13
Published