---
id: CVE-2026-76977
title: >-
  SAP UI5 does not sufficiently validate the parent frame's origin against the
  configured allowlist
summary: >-
  SAP UI5 does not sufficiently validate the parent frame's origin against the
  configured allowlist. An unauthenticated attacker could host a malicious page
  to bypass framing restrictions. If an authenticated victim visits the
  attacker's p…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-1289
vendor: SAP_SE
product: SAPUI5(Frame Options Allowlist)
affected:
  - sapui5_frame_options_allowlist SAP_UI 750
  - sapui5_frame_options_allowlist 754
  - sapui5_frame_options_allowlist 755
  - sapui5_frame_options_allowlist 756
  - sapui5_frame_options_allowlist 757
  - sapui5_frame_options_allowlist 758
  - sapui5_frame_options_allowlist 816
  - sapui5_frame_options_allowlist UI_700 200
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:12:59.557'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76977'
references:
  - url: 'https://me.sap.com/notes/3783189'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
  - cve.org
epss: 0.00223
epssPercentile: 0.13201
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T10:05:09.058790Z'
ingestedAt: '2026-09-08T15:33:26.981Z'
---

## Overview

SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's page and interacts with it, the attacker could trick the victim into performing unintended actions, resulting in a low impact on integrity. There is no impact on confidentiality and availability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
