Junglewise Threat Intelligence

CVE-2026-34258: SAP SAPUI5 UI misrepresentation in Search UI

CVE-2026-34258 · Severity: medium · CVSS 4.7 · Published 2026-05-12

Vendors: SAP.

Executive brief

SAPUI5, a framework used for building web applications, contains a vulnerability in its Search UI component. An attacker can manipulate web addresses to display malicious content within the application's interface. This could be used to trick users into visiting dangerous websites or disclosing sensitive information by making the malicious content appear as if it is part of the trusted SAP application.

Technical details

A User Interface (UI) Misrepresentation vulnerability (CWE-451) exists in the SAPUI5 Search UI component. The flaw allows an unauthenticated remote attacker to inject malicious content into the UI by manipulating specific URL parameters. While the vulnerability does not directly allow for data modification or service disruption, it can be leveraged for phishing or social engineering attacks by rendering attacker-controlled content within the context of the trusted application. Exploitation requires a victim to interact with a specially crafted link (User Interaction: Required). SAP has released security notes (3726583) to address this issue.

Affected products

  • SAP SAPUI5 (Search UI)

Timeline

  • 2026-05-12: advisory: Published as part of SAP Security Patch Day May 2026

References