PT-2026-81119 · Sap · S/4Hana
CVE-2026-66766
·
Published
2026-08-25
·
Updated
2026-08-27
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SAP S/4HANA (Private Cloud) (affected versions not specified)
Description
SAP S/4HANA (Private Cloud) utilizes a third-party component susceptible to a Regular Expression Denial of Service (ReDoS), a condition where a specially crafted input causes the regular expression engine to take an exponential amount of time to process, leading to system exhaustion. An unauthenticated attacker can provide malicious input to trigger excessive processing, which may exhaust system resources and render the service unavailable.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
S/4Hana