AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-66774

LOW · CVSS 3.7 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

SAP Approuter is vulnerable due to inconsistent handling of specific error conditions, which may allow an attacker with low privileges to exploit the issue under non-default configurations. Although successful exploitation is complex and relies on external factors, it could lead to a low impact on system availability. Organizations using SAP Approuter should prioritize monitoring and applying best practices for configuration to mitigate potential risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66774
Severity
LOW
CVSS
3.7
EPSS
0.22%

Original NVD Description

SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on conditions outside the attacker's control. This could result in a low impact on availability. There is no impact on confidentiality and integrity.