Session Hijacking Vulnerability in SAP Approuter
CVE-2026-66776

5.9MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 August 2026

What is CVE-2026-66776?

The SAP Approuter vulnerability occurs when the integrity verification for certain session-related request headers is not properly enforced under specific conditions. This allows an attacker with limited privileges to craft a malicious request that can bypass the integrity checks and potentially load the session context of another user. Although this exploitation requires the attacker to have previously viewed matching session values externally, it poses serious risks to user confidentiality while having minimal effects on data integrity.

Affected Version(s)

SAP Business AI Platform (Approuter) SAP Approuter node.js package < 23.0.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.