CVE-2026-66776Medium· 5.9▾ SunlitSAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity c…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute. This could result in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.
approuter < 23.0.0Upgrade past the affected range:
approuter 23.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-66777Medium· 5.9SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations
CVE-2026-66778Medium· 5.3SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components
CVE-2026-58230High· 7.0SAP Approuter does not sufficiently validate certain token content under specific configurations
CVE-2026-58237Medium· 5.9WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality
CVE-2026-58238Medium· 5.9SAP Approuter does not sufficiently handle certain requests under specific conditions
CVE-2026-58239Low· 3.7SAP Approuter does not sufficiently validate tenant context in inbound requests