PT-2026-81119 · Sap · S/4Hana

CVE-2026-66766

·

Published

2026-08-25

·

Updated

2026-08-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SAP S/4HANA (Private Cloud) (affected versions not specified)
Description SAP S/4HANA (Private Cloud) utilizes a third-party component susceptible to a Regular Expression Denial of Service (ReDoS), a condition where a specially crafted input causes the regular expression engine to take an exponential amount of time to process, leading to system exhaustion. An unauthenticated attacker can provide malicious input to trigger excessive processing, which may exhaust system resources and render the service unavailable.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66766

Affected Products

S/4Hana