Cross-Site Scripting Vulnerability in SAP NetWeaver Application Server ABAP
CVE-2026-66779

6.3MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 August 2026

What is CVE-2026-66779?

A Cross-Site Scripting (XSS) vulnerability exists in the SAP NetWeaver Application Server ABAP. This flaw allows authenticated attackers to craft malicious links that, when accessed by another authenticated user, can execute harmful scripts within the user's browser. The malicious code is processed during the rendering of the page on the client side, leading to potential unauthorized actions and exposure of sensitive information. Proper validation and encoding of user inputs are essential to mitigate this vulnerability.

Affected Version(s)

SAP NetWeaver Application Server ABAP SAP_UI 754

SAP NetWeaver Application Server ABAP 755

SAP NetWeaver Application Server ABAP 756

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.