CVE-2026-76977

Summary

SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's page and interacts with it, the attacker could trick the victim into performing unintended actions, resulting in a low impact on integrity. There is no impact on confidentiality and availability.

Affected Software

VendorProductVersion RangeStatus
SAP_SESAPUI5(Frame Options Allowlist)SAP_UI 750affected
SAP_SESAPUI5(Frame Options Allowlist)754affected
SAP_SESAPUI5(Frame Options Allowlist)755affected
SAP_SESAPUI5(Frame Options Allowlist)756affected
SAP_SESAPUI5(Frame Options Allowlist)757affected
SAP_SESAPUI5(Frame Options Allowlist)758affected
SAP_SESAPUI5(Frame Options Allowlist)816affected
SAP_SESAPUI5(Frame Options Allowlist)UI_700 200affected

Weaknesses

  • CWE-1289: CWE-1289: Improper Validation of Unsafe Equivalence in Input

References