CVE-2026-27682: Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages)
Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft a URL that exploits an unprotected URL parameter to embed a malicious script. If a victim clicks the link, the injected input is processed during web page generation, resulting in the execution of malicious content in the victim�s browser context. This could allow the attacker to access and/or modify information, impacting the confidentiality and integrity of the application, with no impact to availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27682?
CVE-2026-27682 is classified as a critical severity vulnerability due to its potential for exploitation.
How do I fix CVE-2026-27682?
To mitigate CVE-2026-27682, it is recommended to apply the latest security patches from SAP for SAP NetWeaver Application Server ABAP.
What type of vulnerability is CVE-2026-27682?
CVE-2026-27682 is a reflected cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-27682?
Organizations using the SAP NetWeaver Application Server ABAP that implement applications based on Business Server Pages are affected by CVE-2026-27682.
Can CVE-2026-27682 be exploited remotely?
Yes, CVE-2026-27682 can be exploited remotely by an unauthenticated attacker through crafted requests.