Medium severity6.1NVD Advisory· Published Aug 11, 2026· Updated Aug 26, 2026
CVE-2026-66771
CVE-2026-66771
Description
SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user subsequently opens the adapted application, the injected script executes in the victim's browser session. Successful exploitation could allow the attacker to access sensitive session data and perform unauthorized actions on behalf of the victim, resulting in a high impact on confidentiality and integrity. There is no impact on availability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
2- Critical SAP Vulnerabilities Let Attackers Inject Malicious Code and Corrupt MemoryCyber Security News · Aug 11, 2026
- SAP: 25 Vulnerabilities Disclosed, Critical Commerce Cloud Flaw Actively ExploitedVypr Intelligence · Aug 11, 2026