# CVE-2026-76977

## Summary

- **CVE ID:** CVE-2026-76977
- **Severity:** MEDIUM
- **CVSS Score:** 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
- **CWE:** CWE-1289
- **Published:** Sep 8, 2026
- **Last Modified:** Sep 8, 2026

## Description

SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's page and interacts with it, the attacker could trick the victim into performing unintended actions, resulting in a low impact on integrity. There is no impact on confidentiality and availability.

## Affected Products

- SAP_SE — SAPUI5(Frame Options Allowlist) (SAP_UI 750)
- SAP_SE — SAPUI5(Frame Options Allowlist) (754)
- SAP_SE — SAPUI5(Frame Options Allowlist) (755)
- SAP_SE — SAPUI5(Frame Options Allowlist) (756)
- SAP_SE — SAPUI5(Frame Options Allowlist) (757)
- SAP_SE — SAPUI5(Frame Options Allowlist) (758)
- SAP_SE — SAPUI5(Frame Options Allowlist) (816)
- SAP_SE — SAPUI5(Frame Options Allowlist) (UI_700 200)

## References

- [CNA](https://me.sap.com/notes/3783189)
- [CNA](https://url.sap/sapsecuritypatchday)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.22%
- **EPSS Percentile:** 12.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._