Uncontrolled Data Flow in SAP Approuter
CVE-2026-66761

4.3MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 August 2026

What is CVE-2026-66761?

SAP Approuter contains a flaw that fails to enforce adequate flow control in specific functionalities. This vulnerability allows an attacker, even with low privileges, to send extensive volumes of data while not properly managing responses. As a result, this can lead to unbounded memory growth, which may lead to performance issues and decreased system availability. Although the integrity and confidentiality of data remain intact, this loophole poses a notable risk to overall service efficiency and uptime.

Affected Version(s)

SAP Business AI Platform (Approuter) SAP Approuter node.js package < 23.0.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.