cbcvebase.
CVE-2026-27690
published 2026-07-14

CVE-2026-27690: Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to…

PriorityP260critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.68%
50.0th percentile
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.

Affected

1 ranges
VendorProductVersion rangeFixed in
sap_sesap_approuter

Detection & IOCsextracted from sources · hover to see the quote

  • Target: SAP Approuter deployments in non-Cloud Foundry environments are specifically affected by this HTTP request smuggling vulnerability
  • Attack vector: Unauthenticated attacker sends a specially crafted HTTP request causing request-response desynchronization; monitor for malformed/ambiguous HTTP requests (e.g., conflicting Content-Length and Transfer-Encoding headers) directed at SAP Approuter endpoints
  • Impact indicators: Successful exploitation results in exposure of other users' HTTP responses and denial-of-service; monitor for unexpected response body leakage or service unavailability on SAP Approuter instances
  • ·Vulnerability is specific to SAP Approuter deployments in non-Cloud Foundry environments; Cloud Foundry-based deployments are not mentioned as affected
  • ·No evidence of in-the-wild exploitation reported at time of disclosure; patching is the recommended remediation
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.