SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-27690

CRITICAL · CVSS 9.1 EPSS 0.69%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

An HTTP Request Smuggling vulnerability in SAP Approuter allows unauthenticated attackers to craft malicious HTTP requests, leading to request-response desynchronization. This can expose sensitive user data and potentially disrupt system availability, posing a significant risk to confidentiality and operational integrity. Organizations using SAP Approuter should prioritize patching this vulnerability to mitigate the associated risks.

CVE
CVE-2026-27690
Severity
CRITICAL
CVSS
9.1
EPSS
0.69%

Original NVD Description

Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.