CVE-2026-27682
published 2026-05-12CVE-2026-27682: Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.22%
12.9th percentile
Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft a URL that exploits an unprotected URL parameter to embed a malicious script. If a victim clicks the link, the injected input is processed during web page generation, resulting in the execution of malicious content in the victim�s browser context. This could allow the attacker to access and/or modify information, impacting the confidentiality and integrity of the application, with no impact to availability.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SAP NetWeaver Application Server ABAP SAP_BASIS 700 up to SAP_BASIS 816 Business Server Page cross site scripting (Nessus ID 314951 / WID-SEC-2026-1466)
vuldb·2026-05-16·CVSS 4.7
CVE-2026-27682 [MEDIUM] SAP NetWeaver Application Server ABAP SAP_BASIS 700 up to SAP_BASIS 816 Business Server Page cross site scripting (Nessus ID 314951 / WID-SEC-2026-1466)
A vulnerability labeled as problematic has been found in SAP NetWeaver Application Server ABAP. The affected element is an unknown function of the component Business Server Page. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-27682. The attack may be performed from remote. There is no available exploit.
It is best practice to apply a patch to resolve this issue.
GHSA
GHSA-xj8w-vw8m-px5f: Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an
ghsa_unreviewed·2026-05-12
CVE-2026-27682 [MEDIUM] CWE-79 GHSA-xj8w-vw8m-px5f: Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an
Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft a URL that exploits an unprotected URL parameter to embed a malicious script. If a victim clicks the link, the injected input is processed during web page generation, resulting in the execution of malicious content in the victim�s browser context. This could allow the attacker to access and/or modify information, impacting the confidentiality and integrity of the application, with no impact to availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-12
Published