Uncontrolled Data Flow in SAP Approuter
CVE-2026-66761
4.3MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-66761?
SAP Approuter contains a flaw that fails to enforce adequate flow control in specific functionalities. This vulnerability allows an attacker, even with low privileges, to send extensive volumes of data while not properly managing responses. As a result, this can lead to unbounded memory growth, which may lead to performance issues and decreased system availability. Although the integrity and confidentiality of data remain intact, this loophole poses a notable risk to overall service efficiency and uptime.
Affected Version(s)
SAP Business AI Platform (Approuter) SAP Approuter node.js package < 23.0.0