CVE-2026-66779
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed and reflected within the DOM on the client side during page rendering, resulting in the execution of malicious content in the victim's browser context. Successful exploitation could result in a high impact to the confidentiality and a low impact to the integrity of the system, while availability remains unaffected.
| Vendor | sap_se |
| Product | sap netweaver application server abap |
| Published | Aug 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for sap_se sap netweaver application server abap
Be the first to know when new medium vulnerabilities affecting sap_se sap netweaver application server abap are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
SAP_SE / SAP NetWeaver Application Server ABAP
SAP_UI 754 755 756 757 758 816 EP-FLP 7.50 SAP_BASIS 731 AJAX-RUNTIME 7.50