CVE-2026-66771 PUBLISHED

Cross Site Scripting (XSS) vulnerability in SAPUI5

Assigner: sap
Reserved: 27.07.2026 Published: 11.08.2026 Updated: 11.08.2026

SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user subsequently opens the adapted application, the injected script executes in the victim's browser session. Successful exploitation could allow the attacker to access sensitive session data and perform unauthorized actions on behalf of the victim, resulting in a high impact on confidentiality and integrity. There is no impact on availability.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
CVSS Score: 6.1

Product Status

Vendor SAP_SE
Product SAPUI5
Versions Default: unaffected
  • Version SAP_UI 750 is affected
  • Version 754 is affected
  • Version 755 is affected
  • Version 756 is affected
  • Version 757 is affected
  • Version 758 is affected
  • Version 816 is affected
  • Version UI_700 200 is affected

References

Problem Types