
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27680 is a CSS injection vulnerability in SAP NetWeaver Application Server ABAP that allows unauthenticated attackers to inject custom Cascading Style Sheets (CSS) into web pages served by the application. When a user accesses or interacts with the affected page, the injected CSS is executed, resulting in a low impact on confidentiality with no impact on integrity or availability. Affected versions include SAP NetWeaver AS ABAP version 816 and SAP_UI version 758. The vulnerability was published on May 14, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 4.3 (Medium) per NVD, or 3.1 (Low) per the GitHub Advisory Database and ENISA (GitHub Advisory, SAP Security Notes).
The root cause is improper input handling (CWE-276: Incorrect Default Permissions, per official classification; CWE-79: Cross-site Scripting is estimated by Feedly) under certain conditions in SAP NetWeaver AS ABAP, which fails to properly sanitize or encode user-supplied data before rendering it in web pages. An unauthenticated remote attacker can craft a malicious request that injects CSS data into a page served by the application; the injected styles execute when a victim user accesses or clicks the affected page, requiring user interaction. The attack vector is network-based with low attack complexity, though the GitHub Advisory notes high attack complexity in its scoring. No public proof-of-concept or technical write-up detailing specific injection endpoints has been identified (GitHub Advisory, SAP Security Notes).
Successful exploitation allows an attacker to manipulate the visual appearance and styling of web pages served by SAP NetWeaver AS ABAP, potentially enabling UI redressing, phishing-style attacks, or limited exposure of confidential information visible on the page. The impact is confined to low confidentiality loss; integrity and availability are not affected. The vulnerability does not enable remote code execution or privilege escalation, limiting its overall severity (GitHub Advisory).
SAP released a security patch on May 14, 2026, addressing this vulnerability; organizations should apply SAP Security Note 3665042 via the SAP Support Portal. As interim mitigations, administrators should implement strict input validation and output encoding for all user-supplied data rendered in web pages, and consider deploying Content Security Policy (CSP) headers to restrict unauthorized CSS injection. Restricting network access to SAP NetWeaver AS ABAP where operationally feasible can further reduce exposure (SAP Security Notes, GitHub Advisory).
The vulnerability was covered as part of SAP's April 2026 Security Patch Day roundups by security firms Onapsis and SecurityBridge, which track SAP-specific vulnerabilities for enterprise customers. No significant independent researcher commentary or broad media coverage has been identified beyond standard patch-day summaries (Onapsis Blog, SecurityBridge Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."