CVE-2026-66766
Received Received - Intake

Regular Expression Denial of Service in SAP S/4HANA Private Cloud

Vulnerability report for CVE-2026-66766, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: SAP SE

Description

SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful exploitation could exhaust system resources and make the service unavailable, resulting in a high impact on availability. There is no impact on confidentiality and integrity.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap s_4hana *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1333 The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Regular Expression Denial of Service (ReDoS) vulnerability in SAP S/4HANA (Private Cloud) caused by a third-party component. An unauthenticated attacker can send specially crafted input to trigger excessive processing, consuming system resources and making the service unavailable.

Detection Guidance

Detection of this ReDoS vulnerability in SAP S/4HANA (Private Cloud) requires monitoring for excessive resource consumption during input processing. Check SAP logs for unusual patterns in requests to the affected component. Use network monitoring tools like Wireshark to inspect traffic for malformed inputs. SAP Security Notes may provide specific detection guidance in their patch notes.

Impact Analysis

The vulnerability can cause service unavailability due to resource exhaustion. It does not affect confidentiality or integrity of data, meaning your information remains secure but the system may become inaccessible during an attack.

Compliance Impact

This vulnerability primarily impacts availability by causing service disruptions through excessive resource consumption. It does not affect confidentiality or integrity of data. Compliance impact depends on the specific regulation and how availability is addressed in its requirements.

Mitigation Strategies

Apply the latest SAP Security Notes from SAP's official patch day resources to address the ReDoS vulnerability in the third-party component used by SAP S/4HANA (Private Cloud).

Monitor SAP's Security Notes page for updates and follow their recommended mitigation steps to prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66766. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart