CVE-2026-27690Critical· 9.1▾ MidnightDue to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user response…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.
approuter < 20.10.0Upgrade past the affected range:
approuter 20.10.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-66777Medium· 5.9SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations
CVE-2026-66778Medium· 5.3SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components
CVE-2026-58230High· 7.0SAP Approuter does not sufficiently validate certain token content under specific configurations
CVE-2026-58237Medium· 5.9WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality
CVE-2026-58238Medium· 5.9SAP Approuter does not sufficiently handle certain requests under specific conditions
CVE-2026-58239Low· 3.7SAP Approuter does not sufficiently validate tenant context in inbound requests