CVE-2026-66771: Cross Site Scripting (XSS) vulnerability in SAPUI5
SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user subsequently opens the adapted application, the injected script executes in the victim's browser session. Successful exploitation could allow the attacker to access sensitive session data and perform unauthorized actions on behalf of the victim, resulting in a high impact on confidentiality and integrity. There is no impact on availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66771?
CVE-2026-66771 has a medium severity rating of 6.1.
How do I fix CVE-2026-66771?
To mitigate CVE-2026-66771, ensure that users with content adaptation privileges are restricted and apply any available SAP security patches.
What type of vulnerability is CVE-2026-66771?
CVE-2026-66771 is a Cross Site Scripting (XSS) vulnerability found in SAPUI5.
Who is affected by CVE-2026-66771?
CVE-2026-66771 affects SAPUI5 applications where key users can alter content with potential malicious scripts.
What could happen if CVE-2026-66771 is exploited?
Exploitation of CVE-2026-66771 could allow attackers to execute arbitrary scripts in a victim's browser session, leading to data theft or other malicious activities.