---
id: CVE-2026-66761
title: >-
  SAP Approuter does not enforce sufficient flow control in certain
  functionality
summary: >-
  SAP Approuter does not enforce sufficient flow control in certain
  functionality. An attacker with low privileges could send high volumes of data
  without consuming responses, causing unbounded memory growth. This results in
  a low impact o…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-770
vendor: sap
product: approuter
affected:
  - approuter < 23.0.0
patched:
  - approuter 23.0.0
published: '2026-08-11'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:20:15.443'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-66761'
references:
  - url: 'https://me.sap.com/notes/3786038'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
epss: 0.00382
epssPercentile: 0.29427
ingestedAt: '2026-09-08T21:11:12.274Z'
---

## Overview

SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity.

## Affected

- `approuter < 23.0.0`

## Remediation

Upgrade past the affected range:

- `approuter 23.0.0`
