CVE-2026-66778
Received Received - Intake

SAP Approuter Header Sanitization Bypass Leads to Information Disclosure

Vulnerability report for CVE-2026-66778, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: SAP SE

Description

SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap approuter *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-644 The product does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers, such as Flash.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SAP Approuter fails to properly sanitize specific request headers before passing them to internal components. This allows an unauthenticated attacker to craft a malicious request and gain limited unauthorized access to information, resulting in low confidentiality impact.

Detection Guidance

Detecting this vulnerability requires inspecting HTTP request headers for unusual or crafted values. Monitor for requests with abnormal headers like 'X-Forwarded-For', 'Host', or custom headers that may bypass SAP Approuter sanitization. Use network traffic analysis tools such as Wireshark or tcpdump to capture and inspect incoming requests. Check SAP Approuter logs for suspicious patterns or unexpected header values.

Impact Analysis

An attacker could exploit this to access some sensitive information, though the impact is limited. There is no risk to data integrity or system availability.

Compliance Impact

This vulnerability may pose a compliance risk under GDPR or HIPAA due to unauthorized access to information, potentially violating confidentiality requirements. Organizations should assess their exposure and apply mitigations.

Mitigation Strategies

Update SAP Approuter to the latest patched version to ensure proper sanitization of request headers. Monitor network traffic for unusual requests targeting internal components. Apply network-level protections to filter malicious headers before they reach SAP Approuter.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66778. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart