CVE-2026-44768
SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the application. Confidentiality and availability are not impacted.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
- EPSS probability
- 0.26%
- CWE
- CWE-15
- Published
- 2026-07-14
- Last modified
- 2026-07-14
Affected products
- SAP_SE SAP CRM (WebClient UI)
- SAP_SE SAP CRM (WebClient UI)
- SAP_SE SAP CRM (WebClient UI)
Weakness type
Related vulnerabilities
- CVE-2026-85217 — Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop
- CVE-2026-19592 — OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS...
- CVE-2026-19593 — OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree...
- CVE-2026-16708 — IBM Db2 Mirror for i is affected by multiple vulnerabilities
- CVE-2026-19884 — In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control...
- CVE-2026-73661 — FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup
- CVE-2026-66065 — Ouroboros: Untrusted project .env can still reach RCE via omitted execution-routing keys (Incomplete fix of CVE-2026-47211)
- CVE-2026-56567 — HCL iControl is affected by multiple security vulnerabilities.