cbcvebase.
CVE-2026-66761
published 2026-08-11

CVE-2026-66761: SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without…

PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
0.22%
12.9th percentile
SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity.

Affected

1 ranges
VendorProductVersion rangeFixed in
sap_sesap_business_ai_platform
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.