SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-44752

HIGH · CVSS 8.2 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

SAP NetWeaver Application Server Java is vulnerable to unauthenticated JavaScript injection via specially crafted URLs, enabling attackers to execute malicious scripts in victims' browsers. This vulnerability compromises the confidentiality of sensitive session information while minimally affecting data integrity. Organizations using this application should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-44752
Severity
HIGH
CVSS
8.2
EPSS
0.26%
Java

Original NVD Description

SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the client�s browser. This results in a high impact on confidentiality, low impact on integrity with no impact on availability of the application.