Junglewise Threat Intelligence

CVE-2026-66771: SAP SAPUI5 stored cross-site scripting in content adaptation

CVE-2026-66771 · Severity: medium · CVSS 6.1 · Published 2026-08-11

Vendors: SAP.

Executive brief

SAP SAPUI5 is a framework for building enterprise web applications. A user with content adaptation privileges can inject malicious script code into persisted application configurations. When other users open the adapted application, the injected script runs in their browser, potentially allowing attackers to steal session data or perform unauthorized actions on behalf of victims.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in SAPUI5's content adaptation feature. A key user with content adaptation privileges can inject malicious JavaScript code into persisted application changes. When another user subsequently opens the adapted application, the injected script executes in the victim's browser session with their privileges. The vulnerability requires the attacker to hold content adaptation privileges initially, but the execution is automatic when the victim accesses the modified application. Successful exploitation allows theft of sensitive session data and unauthorized actions on behalf of the victim with no patch information currently available.

Affected products

  • SAP SAPUI5

Timeline

  • 2026-08-11: disclosed

References