CVE-2026-44745
published 2026-07-14CVE-2026-44745: SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated…
PriorityP351high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
EPSS
0.47%
38.7th percentile
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | approuter | >= 0 < 21.2.0 | 21.2.0 |
| sap_se | sap_approuter | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SAP Approuter OAuth2 Login Flow improper authorization
vuldb·2026-07-14·CVSS 8.1
CVE-2026-44745 [HIGH] SAP Approuter OAuth2 Login Flow improper authorization
A vulnerability identified as critical has been detected in SAP Approuter. The affected element is an unknown function of the component OAuth2 Login Flow. Performing a manipulation results in improper authorization.
This vulnerability is cataloged as CVE-2026-44745. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
SAP Approuter has an Open Redirect vulnerability
ghsa·2026-07-14
CVE-2026-44745 [HIGH] CWE-601 SAP Approuter has an Open Redirect vulnerability
SAP Approuter has an Open Redirect vulnerability
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.
GHSA
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations.
ghsa_unreviewed·2026-07-14
CVE-2026-44745 [HIGH] CWE-601 SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations.
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-14
Published