CVE-2026-66774
Received Received - Intake

SAP Approuter Error Handling Flaw Leads to Low Availability Impact

Vulnerability report for CVE-2026-66774, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: SAP SE

Description

SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on conditions outside the attacker's control. This could result in a low impact on availability. There is no impact on confidentiality and integrity.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap approuter *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-754 The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SAP Approuter fails to consistently handle specific error conditions. An attacker with low privileges could exploit this issue if the system is configured non-default. Exploitation is highly complex due to dependencies on external factors. The impact is limited to low availability disruption with no effect on confidentiality or integrity.

Detection Guidance

Detection of this vulnerability requires checking SAP Approuter configurations for non-default settings that may mishandle error conditions. Monitor logs for unusual error patterns or availability issues. No specific commands are provided in the available context.

Impact Analysis

This vulnerability could lead to reduced system availability, causing temporary disruptions in service. It does not allow unauthorized access to data or modification of information, so confidentiality and integrity remain unaffected.

Compliance Impact

This vulnerability has minimal impact on compliance with standards like GDPR or HIPAA. It only affects availability with low impact and does not compromise confidentiality or integrity, which are critical for these regulations.

Mitigation Strategies

Apply the latest security patches provided by SAP for Approuter. Review and adjust non-default configurations to reduce attack surface. Monitor system logs for unusual error conditions or availability issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66774. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart