Vulnerability in SAP Approuter Client Certificate Validation
CVE-2026-66760
6.4MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-66760?
The SAP Approuter has a vulnerability that arises from improper validation of client certificates during specific callback flows. An attacker, even with basic access rights, can exploit this by using a certificate from a trusted authority, which matches the required subject values, thereby evading the identity checks. Although executing this attack may be complex, successful attempts allow the attacker to impersonate a trusted internal component, posing significant risks to the integrity of the system while maintaining lower impacts on confidentiality and availability. Stay informed on patches and updates from SAP to mitigate potential risks.
Affected Version(s)
SAP Business AI Platform (Approuter) SAP Approuter node.js package < 23.0.0