SAP NetWeaver Application Server ABAP: cross-site scripting
Medium6.3CVE-2026-66779 · Published Aug 11, 2026 · updated Aug 26, 2026
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed and reflected within the DOM on the client side during page rendering, resulting in the execution of malicious content in the victim's browser context. Successful exploitation could result in a high impact to the confidentiality and a low impact to the integrity of the system, while availability remains unaffected.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SAP NetWeaver Application Server ABAP Product | <= SAP_UI 754 | No fix yet |
| <= 755 | No fix yet | |
| <= 756 | No fix yet | |
| <= 757 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-79
More SAP advisories
All SAP| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | SAP Commerce Cloud (Data Hub Adapter): remote code execution | Critical10.0 | No fix yet |
| Aug 11 | SAP Business AI Platform (Approuter): improper signature check | Medium5.9 | No fix yet |
| Aug 11 | SAP Business AI Platform (Approuter): path traversal | Medium5.9 | No fix yet |
| Aug 11 | SAP Approuter does not sufficiently sanitize certain request headers before... | Medium5.3 | No fix yet |
| Aug 11 | SAP BusinessObjects Business Intelligence Platform (Central : hard-coded key | High7.9 | No fix yet |
| Aug 11 | SAP S/4 HANA (Reprocess Bank Statement Items): privilege escalation | Medium4.3 | No fix yet |