CVE-2026-66771
Received Received - Intake

Stored XSS in SAPUI5 Application via Content Adaptation

Vulnerability report for CVE-2026-66771, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: SAP SE

Description

SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user subsequently opens the adapted application, the injected script executes in the victim's browser session. Successful exploitation could allow the attacker to access sensitive session data and perform unauthorized actions on behalf of the victim, resulting in a high impact on confidentiality and integrity. There is no impact on availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap sapui5 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user opens the adapted application, the injected script executes in their browser session. This can lead to unauthorized access to sensitive session data and actions on behalf of the victim.

Detection Guidance

This vulnerability involves malicious script injection in SAPUI5 applications by a key user with content adaptation privileges. Detection requires monitoring for unauthorized script changes in application configurations and user sessions. Check SAPUI5 application logs for unusual script modifications or unauthorized content adaptation activities. Review browser console logs for unexpected script executions when users access adapted applications.

Impact Analysis

If you are a user of an SAPUI5 application adapted by a malicious key user, your session data could be accessed without authorization. Attackers may perform actions on your behalf, compromising confidentiality and integrity of your data. No impact on system availability is expected.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive personal or health data, violating GDPR and HIPAA compliance. Organizations may face legal penalties, data breach notifications, and reputational damage due to compromised data integrity and confidentiality.

Mitigation Strategies

Restrict content adaptation privileges to trusted key users only. Monitor application changes for unauthorized script injections. Apply SAPUI5 security patches or updates as soon as available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66771. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart