Data Exposure Vulnerability in SAP OData Services
CVE-2026-66773

5.9MEDIUM

Key Information:

Vendor

SAP

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-66773?

A vulnerability exists in SAP's OData services that allows a malicious actor to obtain sensitive authentication information and inject unauthorized data into applications. This poses a significant risk to confidentiality, as attackers can leverage this flaw to access sensitive information without proper authorization. Consequently, organizations utilizing these services must be vigilant and apply the necessary security patches to mitigate potential data breaches.

Affected Version(s)

Odata pyodata (pip) < 1.11.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.