CVE-2026-76977
Received Received - Intake

SAP UI5 Origin Validation Bypass via Malicious Page

Vulnerability report for CVE-2026-76977, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: SAP SE

Description

SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's page and interacts with it, the attacker could trick the victim into performing unintended actions, resulting in a low impact on integrity. There is no impact on confidentiality and availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap ui5 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1289 The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SAP UI5 does not properly check if a parent frame is allowed to embed it. An attacker can create a malicious webpage that bypasses these restrictions. When a logged-in user visits this page and interacts with it, the attacker may trick the user into performing unintended actions, affecting the system's integrity.

Impact Analysis

If you are an authenticated user of a system using SAP UI5, an attacker could trick you into performing actions you did not intend by hosting a malicious page. This could lead to unauthorized changes or actions in the system, but does not expose data or disrupt service.

Compliance Impact

This vulnerability primarily impacts integrity by allowing unauthorized actions. It does not directly affect confidentiality or availability. Compliance impact would depend on whether unauthorized actions violate specific regulatory requirements, but no direct impact on GDPR or HIPAA is mentioned.

Mitigation Strategies

Review and update the allowlist for parent frame origins in SAP UI5 to ensure only trusted domains are permitted. Monitor network traffic for suspicious framing attempts or unauthorized interactions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76977. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart