Vulnerability in SAP Approuter Client Certificate Validation
CVE-2026-66760

6.4MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 August 2026

What is CVE-2026-66760?

The SAP Approuter has a vulnerability that arises from improper validation of client certificates during specific callback flows. An attacker, even with basic access rights, can exploit this by using a certificate from a trusted authority, which matches the required subject values, thereby evading the identity checks. Although executing this attack may be complex, successful attempts allow the attacker to impersonate a trusted internal component, posing significant risks to the integrity of the system while maintaining lower impacts on confidentiality and availability. Stay informed on patches and updates from SAP to mitigate potential risks.

Affected Version(s)

SAP Business AI Platform (Approuter) SAP Approuter node.js package < 23.0.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.