๐Ÿ” CVE Alert

CVE-2026-66777

MEDIUM 5.9

Multiple vulnerabilities in SAP Business AI Platform (Approuter)

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the required conditions, an attacker with low privileges could send specially crafted requests to bypass authorization checks and reach protected resources beyond their assigned scope. Successful exploitation could allow the attacker to read sensitive data and perform limited modifications on protected resources, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.

Vendor sap_se
Product sap business ai platform (approuter)
Published Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for sap_se sap business ai platform (approuter)

Be the first to know when new medium vulnerabilities affecting sap_se sap business ai platform (approuter) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

SAP_SE / SAP Business AI Platform (Approuter)
SAP Approuter node.js package < 23.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
me.sap.com: https://me.sap.com/notes/3786038 url.sap: https://url.sap/sapsecuritypatchday