Cross-Site Scripting Vulnerability in SAP NetWeaver Application Server ABAP
CVE-2026-66779
6.3MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-66779?
A Cross-Site Scripting (XSS) vulnerability exists in the SAP NetWeaver Application Server ABAP. This flaw allows authenticated attackers to craft malicious links that, when accessed by another authenticated user, can execute harmful scripts within the user's browser. The malicious code is processed during the rendering of the page on the client side, leading to potential unauthorized actions and exposure of sensitive information. Proper validation and encoding of user inputs are essential to mitigate this vulnerability.
Affected Version(s)
SAP NetWeaver Application Server ABAP SAP_UI 754
SAP NetWeaver Application Server ABAP 755
SAP NetWeaver Application Server ABAP 756