ZeroHour

CVE-2026-76977

mass

Unauthenticated frame-origin allowlist bypass in SAP UI5 (clickjacking risk)

CVSS 3.1
4.3 medium
EPSS
<1%p13
Published
()
Modified
AI analysis

SAP UI5 does not sufficiently validate the parent frame's origin against its configured allowlist (CWE-1289), allowing framing restrictions to be bypassed. An unauthenticated attacker can host a malicious web page, and if an authenticated victim visits that page and interacts with it, the attacker can trick the victim into performing unintended actions in the UI5 application — a clickjacking-style attack. The result is a low impact on integrity only, with no impact on confidentiality or availability (CVSS 3.1 score 4.3, medium). Any organization running SAP UI5-based frontends, the UI framework underlying SAP Fiori applications, is potentially affected where frame-origin allowlists are relied upon. There is no known public proof-of-concept, the issue is not listed in CISA KEV, and EPSS is 0.2% (13th percentile), indicating exploitation risk is currently low.

What to do: Apply the SAP UI5 fix delivered in SAP's September 2026 Security Patch Day and check the SAP note for this CVE for the exact affected and corrected versions. Review whether your UI5 applications depend on cross-origin framing and parent-frame origin allowlists, and restrict frame-ancestors/framing configuration where cross-origin embedding is not needed. Since exploitation requires an authenticated user to visit and interact with an attacker-controlled page, user awareness and standard web controls (e.g., validating external links) provide practical mitigation; expected impact is limited to unintended user actions, not data disclosure.

Affected
SAP UI5
Estimated exposure
masslikely millions of business users across hundreds of thousands of SAP installations running UI5-based frontends (upper-bound estimate; only deployments relying… — SAP UI5 is the standard UI framework underpinning SAP Fiori/S/4HANA web frontends across SAP's customer base of over 400,000 organizations, though the flaw only matters where framing allowlists are configured, so the true affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's page and interacts with it, the attacker could trick the victim into performing unintended actions, resulting in a low impact on integrity. There is no impact on confidentiality and availability.

Weakness
CWE-1289
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport

SAP's September 2026 Patch Day fixes 19 notes including CVE-2026-44756 (CVSS 10.0), unauthenticated memory corruption in SAP Extended Passport Processing kernels.

SAP shipped 19 new security notes plus one update across NetWeaver, S/4HANA, Integration Suite, Commerce Cloud, and Cloud Application Programming Model. Top issues include CVE-2026-44756 (CVSS 10.0 memory corruption in SAP Extended Passport Processing across many KERNEL and Web Dispatcher versions), CVE-2026-58240 (CVSS 9.8 missing authentication in NetWeaver Message Server), CVE-2026-76969 (CVSS 9.4 credential disclosure in CAP library sap/cds-mtxs), and CVE-2026-66768 (CVSS 9.0 access control flaw in SAP GUI for Java). No exploitation is reported; organizations running affected kernels are urged to patch urgently.