CVE-2026-27680 - CSS Injection vulnerability in SAP NetWeaver Application Server ABAP
CVE ID :CVE-2026-27680
Published : May 14, 2026, 6:33 p.m. | 50 minutes ago
Description :Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result, the issue has a low impact on confidentiality, while integrity and availability are not impacted.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : May 14, 2026, 6:33 p.m. | 50 minutes ago
Description :Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result, the issue has a low impact on confidentiality, while integrity and availability are not impacted.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...