medium2026-08-11SAP NetWeaverCVE-2026-66779

Cross-Site Scripting in SAP NetWeaver Web Dynpro UI Repository

SAP NetWeaver Web Dynpro (UI Repository)

Our Take

Web Dynpro is widely deployed across classic SAP applications. Next planned window.

Vulnerability Detail

Cross-site scripting vulnerability in the UI Repository component of SAP NetWeaver Web Dynpro allows an attacker to inject malicious scripts that execute in the browser context of authenticated users, enabling session hijacking or credential theft.

Patch Action

Apply SAP Note 3721424. Verify affected versions in the official SAP Note.

Patch Info

CVSS Score

6.3

SAP Note

3721424

CVE

CVE-2026-66779

Published

2026-08-11

← All patches