CVE-2026-66761
published 2026-08-11CVE-2026-66761: SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without…
PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
0.22%
12.9th percentile
SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap_se | sap_business_ai_platform | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SAP Approuter resource consumption
vuldb·2026-08-11·CVSS 4.3
CVE-2026-66761 [MEDIUM] SAP Approuter resource consumption
A vulnerability, which was classified as critical, was found in SAP Approuter. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to resource consumption.
This vulnerability is registered as CVE-2026-66761. It is possible to launch the attack remotely. No exploit is available.
GHSA
SAP Approuter does not enforce sufficient flow control in certain functionality.
ghsa_unreviewed·2026-08-11
CVE-2026-66761 [MEDIUM] CWE-770 SAP Approuter does not enforce sufficient flow control in certain functionality.
SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-11
Published