medium2026-08-11SAP NetWeaverCVE-2026-66779
Cross-Site Scripting in SAP NetWeaver Web Dynpro UI Repository
SAP NetWeaver Web Dynpro (UI Repository)
Our Take
Web Dynpro is widely deployed across classic SAP applications. Next planned window.
Vulnerability Detail
Cross-site scripting vulnerability in the UI Repository component of SAP NetWeaver Web Dynpro allows an attacker to inject malicious scripts that execute in the browser context of authenticated users, enabling session hijacking or credential theft.
Patch Action
Apply SAP Note 3721424. Verify affected versions in the official SAP Note.
Patch Info