Cross-site scripting - CVE-2026-44759
Published: July 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in SAP NetWeaver Enterprise Portal when rendering untrusted input. A remote attacker can trick the victim into interacting with crafted content to execute arbitrary script in a victim's browser.
User interaction is required.