{"id":"CVE-2026-27690","title":"Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization","summary":"Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user response…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","cwe":["CWE-444"],"vendor":"sap","product":"approuter","affected":["approuter < 20.10.0"],"patched":["approuter 20.10.0"],"published":"2026-07-14","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:22:05.330","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-27690","references":[{"url":"https://me.sap.com/notes/3720138","label":"cna@sap.com"},{"url":"https://url.sap/sapsecuritypatchday","label":"cna@sap.com"}],"tags":["nvd"],"epss":0.00682,"epssPercentile":0.51073,"ingestedAt":"2026-09-08T21:11:12.257Z","slug":"CVE-2026-27690","body":"## Overview\n\nDue to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.\n\n## Affected\n\n- `approuter < 20.10.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `approuter 20.10.0`","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}