Skip to content
SAPCVE-2026-44767

SAP @ui5/webcomponents-base: clickjacking

Medium6.1CVE-2026-44767 · Published Jul 14, 2026

setThemeRoot() failed to enforce the sap-allowed-theme-origins allowlist. An attacker-controlled absolute cross-origin URL could be stored and used directly to construct a <link rel=stylesheet> element, even when no <meta name=sap-allowed-theme-origins> tag was present in the document. The same bypass was reachable via the ?sap-themeRoot URL parameter.Exploitation requires attacker-influenced input (e.g., a URL query parameter, tenant configuration, or user-supplied setting) to reach setThemeRoot(). A successful exploit allows an attacker to inject arbitrary CSS into the victim page, enabling:- UI redressing and clickjacking- Phishing overlays- Visual defacement- Limited data exfiltration via CSS attribute selectors targeting predictable DOM content

SAP advisory

Affected versions

PackageAffectedFixed in
@ui5/webcomponents-base
Product
<= @ui5/webcomponents-base < 2.21.0No fix yet
Details and references

More SAP advisories

All SAP
Advisory
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented...
Critical9.1Jul 14
SAP CRM (WebClient UI): attacker could inject
Medium4.1Jul 14
SAP S/4HANA Project Management (PPM-PRO): SQL injection
Medium5.5Jul 14
SAP S/4 HANA (Create Single Payment): missing authorization
Medium4.3Jul 14
SAP S/4HANA (Draft operation): privilege escalation
Medium4.3Jul 14
SAP Change and Transport System Attach Tool (ctsattach): unsafe deserialization
High7.6Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.