cbcvebase.
CVE-2026-66760
published 2026-08-11

CVE-2026-66760: SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same…

PriorityP341medium6.4CVSS 3.1
AVNACHPRLUINSUCLIHAL
EPSS
0.12%
2.1th percentile
SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check. This complexity makes the attack difficult to execute. Successful exploitation could allow impersonation of a trusted internal component, resulting in a high impact on integrity and a low impact on confidentiality and availability.

Affected

1 ranges
VendorProductVersion rangeFixed in
sap_sesap_business_ai_platform
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.