medium2026-08-11SAPUI5CVE-2026-66771
Cross-Site Scripting in SAPUI5 Core Framework
SAPUI5 Core Framework
Our Take
SAPUI5 is the foundation of every Fiori application — this XSS has a broad blast surface. Standard planned window, but this affects every Fiori user in your landscape.
Vulnerability Detail
Cross-site scripting vulnerability in the SAPUI5 Core Framework allows an attacker to inject malicious scripts through crafted UI5 content, executing in the browser context of users interacting with affected UI5-based applications — including all Fiori applications built on the affected framework version.
Patch Action
Apply SAP Note 3772071. Verify affected versions in the official SAP Note.
Patch Info