Junglewise Threat Intelligence

CVE-2026-27682: SAP NetWeaver AS ABAP reflected XSS in Business Server Pages

CVE-2026-27682 · Severity: medium · CVSS 4.7 · Published 2026-05-12

Technologies: SAP NetWeaver Application Server ABAP. Vendors: SAP.

Executive brief

SAP NetWeaver Application Server ABAP is a foundational platform for running SAP business applications. A security vulnerability in its web-based components allows an attacker to trick a user into clicking a malicious link, which then executes unauthorized scripts in the user's browser. This could allow an attacker to view or modify sensitive information within the user's session, potentially compromising business data or user accounts.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in SAP NetWeaver Application Server ABAP within applications based on Business Server Pages (BSP). The flaw stems from improper neutralization of input in an unprotected URL parameter. An unauthenticated remote attacker can exploit this by crafting a malicious URL and enticing a victim to click it. Upon interaction, the malicious script is reflected back and executed within the context of the victim's browser session. This allows for the unauthorized access or modification of application data (impacting confidentiality and integrity), though it does not directly affect service availability. SAP has released security notes (e.g., 3728690) to address this issue.

Affected products

  • SAP NetWeaver Application Server ABAP (Business Server Pages) 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918

Timeline

  • 2026-05-12: advisory: Initial disclosure by SAP and NVD
  • 2026-06-03: other: NVD analysis and CPE information added

References

Related threats