SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-44760

MEDIUM · CVSS 4.7 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

The vulnerability affects applications using the Business Server Pages framework in SAP NetWeaver Application Server ABAP, allowing for Cross-Site Scripting (XSS) due to unsanitized input in HTTP responses. Attackers can exploit this flaw to inject and execute arbitrary JavaScript, potentially leading to session hijacking and unauthorized actions on behalf of users. Organizations utilizing this framework should prioritize remediation to mitigate risks associated with user data and session security.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-44760
Severity
MEDIUM
CVSS
4.7
EPSS
0.14%
Java

Original NVD Description

Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeaver Application Server ABAP reflects unsanitized input into the HTTP response which allows an attacker to inject and execute arbitrary JavaScript code under certain conditions. Successful exploitation could allow the attacker to steal session information, perform authenticated actions on behalf of the victim user etc. This vulnerability has low impact on confidentiality and integrity of the data and no impact on application 's availability.