CVE-2026-66778CWE-644

CVE-2026-66778

Medium · published August 11, 2026

CVSS v3.1
5.3
EPSS
0%
Percentile
14.3
In the wild
Unconfirmed
What it is

SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00234 · 14.3th percentile
Weakness
CWE-644 · Improper Neutralization of HTTP Headers for Scripting Syntax
Published
2026-08-11T05:17Z
References (2)
EPSS history
Timeline
  • 11 AUG 00:19Z
    Multiple vulnerabilities in SAP Business AI Platform (Approuter)
    cvelistv5