← Vulnerability feed

Vulnerability record · CVE-2026-66760 · published 11 August 2026

CVE-2026-66760: Sap approuter improper certificate validation vulnerability

Sap · Approuter

SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check. This complexity makes the attack difficult to execute. Successful exploitation could allow impersonation of a trusted internal component, resulting in a high impact on integrity and a low impact on confidentiality and availability.

6.4 CVSS 3.1 Medium EPSS 0.18% · top 93.1% CWE-295 · Improper certificate validation
6.4CVSS 3.1 base score
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
8 Sep 2026Last modified by NVD

Description

SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check. This complexity makes the attack difficult to execute. Successful exploitation could allow impersonation of a trusted internal component, resulting in a high impact on integrity and a low impact on confidentiality and availability.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://me.sap.com/notes/3786038 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory

Track CVE-2026-66760 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2026-27690Sap approuter http request smuggling vulnerabilityDue to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads t…EPSS 0.68%8.1CVE-2026-44745Sap approuter open redirect vulnerabilitySAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthent…EPSS 0.47%7.0CVE-2026-58230Sap approuter open redirect vulnerabilitySAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially …EPSS 0.31%5.9CVE-2026-66776Sap approuter improper verification of cryptographic signature vulnerabilitySAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker …EPSS 0.20%5.9CVE-2026-66777Sap approuter path traversal vulnerabilitySAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the r…EPSS 0.44%5.9CVE-2026-58237Sap approuter missing authorization vulnerabilityWebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit t…EPSS 0.28%5.9CVE-2026-58238Sap approuter allocation without limits vulnerabilitySAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input…EPSS 0.43%5.3CVE-2026-66778Sap approuter vulnerabilitySAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker co…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2026-66760), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.