Vulnerability Description
Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result, the issue has a low impact on confidentiality, while integrity and availability are not impacted.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Application Server Abap | 758 |
Related Weaknesses (CWE)
References
- https://me.sap.com/notes/3665042Permissions Required
- https://url.sap/sapsecuritypatchdayVendor Advisory
FAQ
What is CVE-2026-27680?
CVE-2026-27680 is a vulnerability with a CVSS score of 3.1 (LOW). Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the appli...
How severe is CVE-2026-27680?
CVE-2026-27680 has been rated LOW with a CVSS base score of 3.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-27680?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver Application Server Abap.