PT-2026-57936 · Sap · Sap Approuter

CVE-2026-44745

·

Published

2026-07-14

·

Updated

2026-07-14

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions SAP Approuter (affected versions not specified)
Description SAP Approuter fails to properly validate incoming request headers during the OAuth2 login flow under specific configurations. This flaw allows an unauthenticated remote attacker to craft a malicious link that, if clicked by a victim, can lead to unauthorized access to protected information, impacting confidentiality and integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09912
CVE-2026-44745
GHSA-44P5-3M5G-VFHJ

Affected Products

Sap Approuter