CVE-2026-44768: Security misconfiguration in SAP CRM (WebClient UI)
SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the application. Confidentiality and availability are not impacted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44768?
CVE-2026-44768 has a medium severity score of 4.1.
What type of vulnerability is CVE-2026-44768?
CVE-2026-44768 is categorized as a security misconfiguration in SAP CRM WebClient UI.
What is the impact of CVE-2026-44768?
The impact of CVE-2026-44768 is low on the integrity of the application.
How can I fix CVE-2026-44768?
To fix CVE-2026-44768, it is recommended to configure a Content Security Policy for the SAP CRM WebClient UI.
What kind of attack does CVE-2026-44768 allow?
CVE-2026-44768 allows an attacker to inject and execute malicious scripts in the application context.