SAP @ui5/webcomponents-base: clickjacking
Medium6.1CVE-2026-44767 · Published Jul 14, 2026
setThemeRoot() failed to enforce the sap-allowed-theme-origins allowlist. An attacker-controlled absolute cross-origin URL could be stored and used directly to construct a <link rel=stylesheet> element, even when no <meta name=sap-allowed-theme-origins> tag was present in the document. The same bypass was reachable via the ?sap-themeRoot URL parameter.Exploitation requires attacker-influenced input (e.g., a URL query parameter, tenant configuration, or user-supplied setting) to reach setThemeRoot(). A successful exploit allows an attacker to inject arbitrary CSS into the victim page, enabling:- UI redressing and clickjacking- Phishing overlays- Visual defacement- Limited data exfiltration via CSS attribute selectors targeting predictable DOM content
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| @ui5/webcomponents-base Product | <= @ui5/webcomponents-base < 2.21.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-79
More SAP advisories
All SAP| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 14 | SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented... | Critical9.1 | No fix yet |
| Jul 14 | SAP CRM (WebClient UI): attacker could inject | Medium4.1 | No fix yet |
| Jul 14 | SAP S/4HANA Project Management (PPM-PRO): SQL injection | Medium5.5 | No fix yet |
| Jul 14 | SAP S/4 HANA (Create Single Payment): missing authorization | Medium4.3 | No fix yet |
| Jul 14 | SAP S/4HANA (Draft operation): privilege escalation | Medium4.3 | No fix yet |
| Jul 14 | SAP Change and Transport System Attach Tool (ctsattach): unsafe deserialization | High7.6 | No fix yet |