SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76977

MEDIUM · CVSS 4.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

SAP UI5 is vulnerable due to inadequate validation of the parent frame's origin against the configured allowlist, allowing an unauthenticated attacker to host a malicious page. If an authenticated user interacts with this page, the attacker could manipulate the user into executing unintended actions, potentially compromising data integrity. Organizations using SAP UI5 should prioritize addressing this vulnerability to mitigate risks associated with user interaction and potential integrity issues.

CVE
CVE-2026-76977
Severity
MEDIUM
CVSS
4.3
EPSS
0.22%

Original NVD Description

SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's page and interacts with it, the attacker could trick the victim into performing unintended actions, resulting in a low impact on integrity. There is no impact on confidentiality and availability.