AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66761

MEDIUM · CVSS 4.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

SAP Approuter is vulnerable due to inadequate flow control, allowing low-privileged attackers to send excessive data without receiving responses, which can lead to unbounded memory growth and potential availability issues. While the impact is categorized as low, organizations using SAP Approuter should prioritize addressing this vulnerability to prevent potential service disruptions.

CVE
CVE-2026-66761
Severity
MEDIUM
CVSS
4.3
EPSS
0.22%

Original NVD Description

SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity.