Authorization Bypass in SAP Approuter
CVE-2026-66777
5.9MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-66777?
The SAP Approuter has a vulnerability that allows for insufficient validation of incoming requests, enabling attackers to send specially crafted payloads to bypass authorization checks. This may give them access to protected resources, potentially allowing unauthorized reading of sensitive information and limited modifications to those resources. While the exploit could impact data confidentiality significantly, the integrity of the data remains largely intact. The vulnerability does not affect the availability of the system.
Affected Version(s)
SAP Business AI Platform (Approuter) SAP Approuter node.js package < 23.0.0