CVE-2026-66775
Received Received - Intake

Cross-Site Request Forgery in SAP Approuter

Vulnerability report for CVE-2026-66775, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: SAP SE

Description

SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link and trick a victim into following it. Successful exploitation could allow the attacker to bind the victim's session to an attacker-controlled identity, resulting in a low impact on integrity. There is no impact on confidentiality and availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap approuter *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SAP Approuter lacks default cross-site request forgery protection during authentication. An attacker can create a malicious link to trick a user into clicking it. This could bind the user's session to an attacker-controlled identity, affecting integrity but not confidentiality or availability.

Impact Analysis

If exploited, an attacker could hijack your session and impersonate you within the SAP Approuter environment. This may lead to unauthorized actions being performed under your identity, though data confidentiality and system availability remain unaffected.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized session binding, which may lead to integrity issues. However, since there is no impact on confidentiality or availability, the overall risk to compliance is likely low.

Mitigation Strategies

Enable cross-site request forgery protection on the authentication flow in SAP Approuter. Configure the application to enforce CSRF tokens or similar mechanisms to prevent unauthorized session binding.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66775. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart