AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66778

MEDIUM · CVSS 5.3 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

SAP Approuter is vulnerable due to inadequate sanitization of specific request headers, allowing unauthenticated attackers to send crafted requests that can lead to limited unauthorized access to information. While the impact on confidentiality is low, there is no effect on integrity or availability. Organizations using SAP Approuter should prioritize addressing this vulnerability to mitigate potential information exposure risks.

CVE
CVE-2026-66778
Severity
MEDIUM
CVSS
5.3
EPSS
0.23%

Original NVD Description

SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability.