AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66779

MEDIUM · CVSS 6.3 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

SAP NetWeaver Application Server ABAP is vulnerable to a Cross-Site Scripting (XSS) flaw that allows authenticated attackers to craft malicious links, which, when accessed by victims, execute harmful scripts in their browsers. This could compromise the confidentiality of sensitive information while posing a lower risk to data integrity. Organizations using this platform should prioritize remediation to protect against potential exploitation by attackers.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66779
Severity
MEDIUM
CVSS
6.3
EPSS
0.20%

Original NVD Description

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed and reflected within the DOM on the client side during page rendering, resulting in the execution of malicious content in the victim's browser context. Successful exploitation could result in a high impact to the confidentiality and a low impact to the integrity of the system, while availability remains unaffected.