Junglewise Threat Intelligence

CVE-2026-27680: SAP NetWeaver AS ABAP CSS injection due to improper input handling

CVE-2026-27680 · Severity: low · CVSS 3.1 · Published 2026-05-14

Technologies: SAP NetWeaver Application Server ABAP. Vendors: SAP.

Executive brief

SAP NetWeaver Application Server ABAP, a foundational platform for running SAP business applications, is vulnerable to a security flaw where an attacker can inject malicious styling code into web pages. If a user visits or interacts with a compromised page, the injected code could be used to subtly alter the page's appearance or potentially capture limited information. This issue primarily affects the privacy of user interactions but does not allow for full system takeover or data deletion.

Technical details

A CSS injection vulnerability exists in SAP NetWeaver Application Server ABAP due to improper validation of user-supplied input. An unauthenticated remote attacker can exploit this by tricking a user into accessing a specially crafted URL or page, leading to the injection of custom Cascading Style Sheets (CSS) data. While the impact is limited to low confidentiality loss (such as potential data exfiltration via CSS selectors or UI redressing), it does not directly allow for script execution (XSS) or modification of application data. The vulnerability is tracked under SAP Security Note 3665042.

Affected products

  • SAP NetWeaver Application Server ABAP 758, 816

Timeline

  • 2026-05-14: disclosed
  • 2026-05-14: advisory

References

Related threats