← Vulnerability feed

Vulnerability record · CVE-2026-66776 · published 11 August 2026

CVE-2026-66776: Sap approuter improper verification of cryptographic signature vulnerability

Sap · Approuter

SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute. This could result in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.

5.9 CVSS 3.1 Medium EPSS 0.20% · top 91.1% CWE-347 · Improper verification of cryptographic signature
5.9CVSS 3.1 base score
0.20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
8 Sep 2026Last modified by NVD

Description

SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute. This could result in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://me.sap.com/notes/3786038 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory

Track CVE-2026-66776 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2026-27690Sap approuter http request smuggling vulnerabilityDue to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads t…EPSS 0.68%8.1CVE-2026-44745Sap approuter open redirect vulnerabilitySAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthent…EPSS 0.47%7.0CVE-2026-58230Sap approuter open redirect vulnerabilitySAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially …EPSS 0.31%6.4CVE-2026-66760Sap approuter improper certificate validation vulnerabilitySAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from …EPSS 0.18%5.9CVE-2026-66777Sap approuter path traversal vulnerabilitySAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the r…EPSS 0.44%5.9CVE-2026-58237Sap approuter missing authorization vulnerabilityWebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit t…EPSS 0.28%5.9CVE-2026-58238Sap approuter allocation without limits vulnerabilitySAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input…EPSS 0.43%5.3CVE-2026-66778Sap approuter vulnerabilitySAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker co…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2026-66776), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.