SAPCVE-2026-66771
SAPUI5: cross-site scripting
Medium6.1CVE-2026-66771 · Published Aug 11, 2026 · updated Aug 26, 2026
SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user subsequently opens the adapted application, the injected script executes in the victim's browser session. Successful exploitation could allow the attacker to access sensitive session data and perform unauthorized actions on behalf of the victim, resulting in a high impact on confidentiality and integrity. There is no impact on availability.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SAPUI5 Product | <= SAP_UI 750 | No fix yet |
| <= 754 | No fix yet | |
| <= 755 | No fix yet | |
| <= 756 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-79
More SAP advisories
All SAP| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | SAP Commerce Cloud (Data Hub Adapter): remote code execution | Critical10.0 | No fix yet |
| Aug 11 | SAP Business AI Platform (Approuter): improper signature check | Medium5.9 | No fix yet |
| Aug 11 | SAP Business AI Platform (Approuter): path traversal | Medium5.9 | No fix yet |
| Aug 11 | SAP Approuter does not sufficiently sanitize certain request headers before... | Medium5.3 | No fix yet |
| Aug 11 | SAP NetWeaver Application Server ABAP: cross-site scripting | Medium6.3 | No fix yet |
| Aug 11 | SAP BusinessObjects Business Intelligence Platform (Central : hard-coded key | High7.9 | No fix yet |