CVE-2025-26662: SAP SE SAP Data Services Management Console

Medium severity, CVSS 4.4. EPSS: 0.2% chance of exploitation in the next 30 days.

The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already logged in, clicks on the compromised link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted.

Affected products

  • SAP SE SAP Data Services Management Console

Published 2025-05-13. Last modified 2026-06-17.