CVE-2026-76977: Clickjacking vulnerability in SAPUI5(Frame Options Allowlist)
SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's page and interacts with it, the attacker could trick the victim into performing unintended actions, resulting in a low impact on integrity. There is no impact on confidentiality and availability.
Affected Software
Event History
Frequently Asked Questions
What conditions are required for exploitation?
An attacker must host a malicious page, and an authenticated victim must visit that page and interact with the framed SAPUI5 application. No attacker authentication or privileges are required.
What is the likely impact if exploitation succeeds?
The attacker may trick the victim into performing unintended actions in the application. The stated impact is limited to integrity; confidentiality and availability are not affected.
Does the issue affect default framing behavior?
The issue concerns validation of a parent frame origin against a configured Frame Options allowlist. The available information does not state whether default configurations use or are affected by such an allowlist.