VDB

CVE-2026-44768

CVE-2026-44768 PUBLISHED CVSS 4.1 MEDIUM

Reported by sap · Published July 14, 2026

SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the application. Confidentiality and availability are not impacted.

Risk Scores

CVSS 3.1
4.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N

Affected Products

VendorProductVersions
SAP_SESAP CRM (WebClient UI)S4FND 104, 105, 106
SAP_SESAP CRM (WebClient UI)S4FND 104, 105, 106

Timeline

  • Jul 14, 2026 EPSS Score
  • Jul 14, 2026 Coalition ESS Score
  • Jul 14, 2026 CVE Published
  • Jul 14, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›