CVE-2026-66778
published 2026-08-11CVE-2026-66778: SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a…
PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.23%
14.6th percentile
SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap_se | sap_business_ai_platform | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components.
ghsa_unreviewed·2026-08-11
CVE-2026-66778 [MEDIUM] CWE-644 SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components.
SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability.
VulDB
SAP Approuter improper authorization (EUVD-2026-55890)
vuldb·2026-08-11·CVSS 5.3
CVE-2026-66778 [MEDIUM] SAP Approuter improper authorization (EUVD-2026-55890)
A vulnerability was found in SAP Approuter. It has been declared as problematic. This issue affects some unknown processing. Such manipulation leads to improper authorization.
This vulnerability is traded as CVE-2026-66778. The attack may be launched remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-11
Published