Security
Loading…

CVE-2026-76977

MEDIUMCVSS 4.3
Description

SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's page and interacts with it, the attacker could trick the victim into performing unintended actions, resulting in a low impact on integrity. There is no impact on confidentiality and availability.

Timeline
Published:September 8th, 2026 1:17 AM
Last modified:September 8th, 2026 1:17 AM
CVSS Scoring

CVSS v3: 4.3 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

Source: NIST NVD · Data may lag official sources by up to one minute