3.1
/ 10
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Description
Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result, the issue has a low impact on confidentiality, while integrity and availability are not impacted.
Basic Information
ID
CVE-2026-27680
Source
sap
Published
May 14, 2026 at 18:33
Modified
May 14, 2026 at 19:17
Affected Product
Vendor
SAP_SE
Product
SAP NetWeaver Application Server ABAP
Version
SAP_UI 758
Affected Versions
SAP_SE SAP NetWeaver Application Server ABAP SAP_UI 758
SAP_SE SAP NetWeaver Application Server ABAP 816
SAP_SE SAP NetWeaver Application Server ABAP 816