medium2026-09-08SAPUI5CVE-2026-76977

Clickjacking via Frame Options Misconfiguration in SAPUI5

SAPUI5

Our Take

Clickjacking in SAPUI5 affects any Fiori or custom UI5 app that lacks frame-busting headers. Low individual severity but broad surface area since UI5 underpins virtually every modern SAP user interface.

Vulnerability Detail

Frame options allowlist misconfiguration in SAPUI5 allows UI redressing attacks (clickjacking). An attacker could embed a SAPUI5 application in an iframe to trick users into unintended actions.

Patch Action

Apply the patch per SAP Note 3783189. Verify affected SAPUI5 version in the official SAP Note.

Patch Info

CVSS Score

4.3

SAP Note

3783189

CVE

CVE-2026-76977

Published

2026-09-08

← All patches