PT-2026-70049 · Sap · Sap Approuter

CVE-2026-66777

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP Approuter (affected versions not specified)
Description SAP Approuter fails to sufficiently validate certain incoming requests before forwarding them to backend destinations. An attacker with low privileges can send specially crafted requests to bypass authorization checks, allowing access to protected resources outside their assigned scope. This can lead to the unauthorized reading of sensitive data and limited modifications of protected resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66777

Affected Products

Sap Approuter