Cross-Site Request Forgery Vulnerability in SAP Approuter
CVE-2026-66775
4.3MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-66775?
The SAP Approuter does not implement default protections against cross-site request forgery, making it susceptible to exploitation. An attacker can craft a false link that, when followed by a victim, could allow the attacker to hijack the victim's session and link it to a malicious identity, potentially compromising session integrity. However, this vulnerability does not affect sensitive data confidentiality or system availability.
Affected Version(s)
SAP Business AI Platform (Approuter) SAP Approuter node.js package < 23.0.0