๐Ÿ” CVE Alert

CVE-2026-66779

MEDIUM 6.3

Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed and reflected within the DOM on the client side during page rendering, resulting in the execution of malicious content in the victim's browser context. Successful exploitation could result in a high impact to the confidentiality and a low impact to the integrity of the system, while availability remains unaffected.

Vendor sap_se
Product sap netweaver application server abap
Published Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for sap_se sap netweaver application server abap

Be the first to know when new medium vulnerabilities affecting sap_se sap netweaver application server abap are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

SAP_SE / SAP NetWeaver Application Server ABAP
SAP_UI 754 755 756 757 758 816 EP-FLP 7.50 SAP_BASIS 731 AJAX-RUNTIME 7.50

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
me.sap.com: https://me.sap.com/notes/3721424 url.sap: https://url.sap/sapsecuritypatchday