medium2026-08-11SAPUI5CVE-2026-66771

Cross-Site Scripting in SAPUI5 Core Framework

SAPUI5 Core Framework

Our Take

SAPUI5 is the foundation of every Fiori application — this XSS has a broad blast surface. Standard planned window, but this affects every Fiori user in your landscape.

Vulnerability Detail

Cross-site scripting vulnerability in the SAPUI5 Core Framework allows an attacker to inject malicious scripts through crafted UI5 content, executing in the browser context of users interacting with affected UI5-based applications — including all Fiori applications built on the affected framework version.

Patch Action

Apply SAP Note 3772071. Verify affected versions in the official SAP Note.

Patch Info

CVSS Score

6.1

SAP Note

3772071

CVE

CVE-2026-66771

Published

2026-08-11

← All patches