CVE-2026-27680

Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result, the issue has a low impact on confidentiality, while integrity and availability are not impacted.
References
Link Resource
https://me.sap.com/notes/3665042 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:netweaver_application_server_abap:758:*:*:*:sap_ui:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:816:*:*:*:*:*:*:*

History

03 Jun 2026, 19:27

Type Values Removed Values Added
References () https://me.sap.com/notes/3665042 - () https://me.sap.com/notes/3665042 - Permissions Required
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Vendor Advisory
CPE cpe:2.3:a:sap:netweaver_application_server_abap:816:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:758:*:*:*:sap_ui:*:*:*
First Time Sap netweaver Application Server Abap
Sap

14 May 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-14 19:16

Updated : 2026-06-03 19:27


NVD link : CVE-2026-27680

Mitre link : CVE-2026-27680

CVE.ORG link : CVE-2026-27680


JSON object : View

Products Affected

sap

  • netweaver_application_server_abap
CWE
CWE-276

Incorrect Default Permissions