Error Handling Issues in SAP Approuter
CVE-2026-66774

3.7LOW

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 August 2026

What is CVE-2026-66774?

The SAP Approuter has identified vulnerabilities related to error handling that may not consistently manage specific error conditions. Under non-default configurations, attackers with low privileges have the opportunity to exploit this vulnerability. However, successful exploitation is considered highly complex, as it hinges on factors beyond the attacker's influence. The potential impact primarily concerns the availability of the system; nonetheless, there are no repercussions concerning confidentiality and integrity.

Affected Version(s)

SAP Business AI Platform (Approuter) SAP Approuter node.js package < 23.0.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.