CVE-2026-66760
Received Received - Intake

SAP Approuter Certificate Validation Bypass

Vulnerability report for CVE-2026-66760, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: SAP SE

Description

SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check. This complexity makes the attack difficult to execute. Successful exploitation could allow impersonation of a trusted internal component, resulting in a high impact on integrity and a low impact on confidentiality and availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap approuter *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SAP Approuter fails to properly validate client certificates during callback flows. An attacker with low privileges could exploit this by using a certificate from the same trusted authority with matching subject values to bypass identity checks. This allows impersonation of a trusted internal component, affecting system integrity.

Impact Analysis

This vulnerability could allow an attacker to impersonate trusted internal components, potentially leading to unauthorized actions or data access. The impact is primarily on system integrity, with secondary effects on confidentiality and availability.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized impersonation of internal components, which may lead to unauthorized access to personal or sensitive data. The integrity impact is high, meaning data could be altered without detection, violating integrity requirements in these regulations.

Mitigation Strategies

Update SAP Approuter to the latest version provided by SAP to address the certificate validation issue. Review and restrict client certificate issuance to trusted authorities only. Monitor callback flows for unauthorized access attempts or anomalies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66760. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart