Regular Expression Denial of Service Vulnerability in SAP S/4HANA (Private Cloud)
CVE-2026-66766

7.5HIGH

Key Information:

Vendor

SAP

Vendor
CVE Published:
25 August 2026

What is CVE-2026-66766?

The SAP S/4HANA (Private Cloud) is affected by a Regular Expression Denial of Service (ReDoS) vulnerability due to the use of a flawed third-party component. This vulnerability allows an unauthenticated attacker to craft specific input that can lead to excessive processing demands within the system. If exploited, the attack can exhaust system resources, causing service disruptions and unavailability without impacting the confidentiality or integrity of the system. Users of SAP S/4HANA are strongly recommended to apply applicable updates provided in security advisories to mitigate this risk.

Affected Version(s)

SAP S/4HANA (Manage Supply Protection) UIS4HOP1 800

SAP S/4HANA (Manage Supply Protection) 900

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.