{"id":"CVE-2026-76977","title":"SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist","summary":"SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's p…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","cwe":["CWE-1289"],"vendor":"SAP_SE","product":"SAPUI5(Frame Options Allowlist)","affected":["sapui5_frame_options_allowlist SAP_UI 750","sapui5_frame_options_allowlist 754","sapui5_frame_options_allowlist 755","sapui5_frame_options_allowlist 756","sapui5_frame_options_allowlist 757","sapui5_frame_options_allowlist 758","sapui5_frame_options_allowlist 816","sapui5_frame_options_allowlist UI_700 200"],"published":"2026-09-08","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:12:59.557","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76977","references":[{"url":"https://me.sap.com/notes/3783189","label":"cna@sap.com"},{"url":"https://url.sap/sapsecuritypatchday","label":"cna@sap.com"}],"tags":["nvd","cve.org"],"epss":0.00223,"epssPercentile":0.13179,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-08T10:05:09.058790Z"},"ingestedAt":"2026-09-08T15:33:26.981Z","slug":"CVE-2026-76977","body":"## Overview\n\nSAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's page and interacts with it, the attacker could trick the victim into performing unintended actions, resulting in a low impact on integrity. There is no impact on confidentiality and availability.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}