CVE-2026-66776
published 2026-08-11CVE-2026-66776: SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low…
PriorityP338medium5.9CVSS 3.1
AVNACHPRLUINSUCHILAN
EPSS
0.14%
3.6th percentile
SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute. This could result in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap_se | sap_business_ai_platform | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions.
ghsa_unreviewed·2026-08-11
CVE-2026-66776 [MEDIUM] CWE-347 SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions.
SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute. This could result in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.
VulDB
SAP Approuter integrity check (EUVD-2026-55888)
vuldb·2026-08-11·CVSS 5.9
CVE-2026-66776 [MEDIUM] SAP Approuter integrity check (EUVD-2026-55888)
A vulnerability was found in SAP Approuter. It has been classified as critical. This vulnerability affects unknown code. This manipulation causes improper validation of integrity check value.
This vulnerability appears as CVE-2026-66776. The attack may be initiated remotely. There is no available exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-11
Published