Authorization Bypass in SAP Approuter
CVE-2026-66777

5.9MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 August 2026

What is CVE-2026-66777?

The SAP Approuter has a vulnerability that allows for insufficient validation of incoming requests, enabling attackers to send specially crafted payloads to bypass authorization checks. This may give them access to protected resources, potentially allowing unauthorized reading of sensitive information and limited modifications to those resources. While the exploit could impact data confidentiality significantly, the integrity of the data remains largely intact. The vulnerability does not affect the availability of the system.

Affected Version(s)

SAP Business AI Platform (Approuter) SAP Approuter node.js package < 23.0.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.