Skip to content
SAPCVE-2026-66779

SAP NetWeaver Application Server ABAP: cross-site scripting

Medium6.3CVE-2026-66779 · Published Aug 11, 2026 · updated Aug 26, 2026

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed and reflected within the DOM on the client side during page rendering, resulting in the execution of malicious content in the victim's browser context. Successful exploitation could result in a high impact to the confidentiality and a low impact to the integrity of the system, while availability remains unaffected.

SAP advisory

Affected versions

PackageAffectedFixed in
SAP NetWeaver Application Server ABAP
Product
<= SAP_UI 754No fix yet
<= 755No fix yet
<= 756No fix yet
<= 757No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-79

More SAP advisories

All SAP
Advisory
SAP Commerce Cloud (Data Hub Adapter): remote code execution
Critical10.0Aug 11
SAP Business AI Platform (Approuter): improper signature check
Medium5.9Aug 11
SAP Business AI Platform (Approuter): path traversal
Medium5.9Aug 11
SAP Approuter does not sufficiently sanitize certain request headers before...
Medium5.3Aug 11
SAP BusinessObjects Business Intelligence Platform (Central : hard-coded key
High7.9Aug 11
SAP S/4 HANA (Reprocess Bank Statement Items): privilege escalation
Medium4.3Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.