What is CVE-2026-44762?
SAP Data Services Management Console has an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives. This weakness could allow an authenticated malicious user, in combination with another vulnerability, to inject and execute malicious scripts.
Azərbaycanca: SAP Data Services Management Console-da həddindən artıq icazə verən Content Security Policy (CSP) konfiqurasiyası və müəyyən məhdudlaşdırıcı direktivlərin çatışmaması mövcuddur. Bu zəiflik autentifikasiya olunmuş zərərli istifadəçiyə başqa bir boşluqla birlikdə zərərli skript yeridib icra etməyə imkan verə bilər.
Related CVEs
link basis: same weakness class CWE-1188
FAQ2
What is the primary security issue related to the Content Security Policy (CSP) in SAP Data Services Management Console?
According to CVE-2026-44762, the platform has an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives.
How can this weakness be exploited?
This weakness could allow an authenticated malicious user, in combination with another vulnerability, to inject and execute malicious scripts.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.