VDB
CVE-2026-34258
CVE-2026-34258
PUBLISHED
CVSS 4.699999809265137 MEDIUM
SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include malicious content. Successful exploitation may mislead victim users into clicking and accessing attacker-controlled pages rendered by the application. This vulnerability has a low impact on confidentiality with no effect on the integrity and availability of the application.
EPSS 0.02% · 3.1th percentile
Risk Scores
CVSS 3.1
4.699999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
EPSS Score
0.02%
3.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP_SE | SAPUI5 (Search UI) | SAPUI5 1.108, 1.120, 1.136 |
Timeline
- May 12, 2026 CVE Published
- May 12, 2026 Security Advisory
- May 12, 2026 CVE Updated
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score