CVE-2026-66771

Summary

SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user subsequently opens the adapted application, the injected script executes in the victim's browser session. Successful exploitation could allow the attacker to access sensitive session data and perform unauthorized actions on behalf of the victim, resulting in a high impact on confidentiality and integrity. There is no impact on availability.

Affected Software

VendorProductVersion RangeStatus
SAP_SESAPUI5SAP_UI 750affected
SAP_SESAPUI5754affected
SAP_SESAPUI5755affected
SAP_SESAPUI5756affected
SAP_SESAPUI5757affected
SAP_SESAPUI5758affected
SAP_SESAPUI5816affected
SAP_SESAPUI5UI_700 200affected

Weaknesses

  • CWE-79: CWE-79: Improper Neutralization of Input During Web Page Generation

References