{"id":"CVE-2026-44745","title":"SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations","summary":"SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could …","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","cwe":["CWE-601"],"vendor":"sap","product":"approuter","affected":["approuter < 21.2.0"],"patched":["approuter 21.2.0"],"published":"2026-07-14","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:20:34.980","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-44745","references":[{"url":"https://me.sap.com/notes/3741519","label":"cna@sap.com"},{"url":"https://url.sap/sapsecuritypatchday","label":"cna@sap.com"}],"tags":["nvd"],"epss":0.00466,"epssPercentile":0.39409,"ingestedAt":"2026-09-08T21:11:12.257Z","slug":"CVE-2026-44745","body":"## Overview\n\nSAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.\n\n## Affected\n\n- `approuter < 21.2.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `approuter 21.2.0`","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}