Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap Se
Sap Se sap Business Ai Platform (approuter) |
|
| Vendors & Products |
Sap Se
Sap Se sap Business Ai Platform (approuter) |
Tue, 11 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute. This could result in a high impact on confidentiality and a low impact on integrity. There is no impact on availability. | |
| Title | Multiple vulnerabilities in SAP Business AI Platform (Approuter) | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-08-11T14:27:15.810Z
Reserved: 2026-07-27T17:33:56.949Z
Link: CVE-2026-66776
Updated: 2026-08-11T14:27:11.373Z
Status : Received
Published: 2026-08-11T01:17:24.030
Modified: 2026-08-11T15:17:34.050
Link: CVE-2026-66776
No data.
OpenCVE Enrichment
Updated: 2026-08-11T14:20:25Z