Skip to content
SAPCVE-2026-76977

SAP UI5 does not sufficiently validate the parent frame's origin against the...

Medium4.3CVE-2026-76977 · Published Sep 8, 2026

SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's page and interacts with it, the attacker could trick the victim into performing unintended actions, resulting in a low impact on integrity. There is no impact on confidentiality and availability.

SAP advisory

Affected versions

PackageAffectedFixed in
SAPUI5(Frame Options Allowlist)
Product
<= SAP_UI 750No fix yet
<= 754No fix yet
<= 755No fix yet
<= 756No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-1289

More SAP advisories

All SAP
Advisory
SAP NetWeaver and ABAP Platform: missing authorization
Medium4.3Sep 8
SAP NetWeaver Business Client: code execution
High7.8Sep 8
SAP Web Dispatcher, Internet: information disclosure
Medium6.5Sep 8
SAP Cloud Application Programming Model (CAP): weakly protected credentials
Critical9.4Sep 8
SAP Manufacturing Integration and Intelligence: server-side request forgery
Medium6.5Sep 8
SAP Integration Suite: resource exhaustion
High8.5Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.