---
id: CVE-2026-27690
title: >-
  Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an
  unauthenticated attacker could send a specially crafted HTTP request that
  leads to request-response desynchronization
summary: >-
  Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an
  unauthenticated attacker could send a specially crafted HTTP request that
  leads to request-response desynchronization. This could result in the exposure
  of user response…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'
cwe:
  - CWE-444
vendor: sap
product: approuter
affected:
  - approuter < 20.10.0
patched:
  - approuter 20.10.0
published: '2026-07-14'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:22:05.330'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-27690'
references:
  - url: 'https://me.sap.com/notes/3720138'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
epss: 0.00682
epssPercentile: 0.50368
ingestedAt: '2026-09-08T21:11:12.257Z'
---

## Overview

Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.

## Affected

- `approuter < 20.10.0`

## Remediation

Upgrade past the affected range:

- `approuter 20.10.0`
