Skip to content
SAPCVE-2026-66773

SAP Odata: information disclosure

Medium5.9CVE-2026-66773 · Published Aug 11, 2026 · updated Aug 26, 2026

A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data into the application, which may leads to a high impact on confidentiality and low impact on integrity and no impact on Availability.

SAP advisory

Affected versions

PackageAffectedFixed in
Odata
Product
<= pyodata (pip) < 1.11.2No fix yet
Details and references

More SAP advisories

All SAP
Advisory
SAP Commerce Cloud (Data Hub Adapter): remote code execution
Critical10.0Aug 11
SAP Business AI Platform (Approuter): improper signature check
Medium5.9Aug 11
SAP Business AI Platform (Approuter): path traversal
Medium5.9Aug 11
SAP Approuter does not sufficiently sanitize certain request headers before...
Medium5.3Aug 11
SAP NetWeaver Application Server ABAP: cross-site scripting
Medium6.3Aug 11
SAP BusinessObjects Business Intelligence Platform (Central : hard-coded key
High7.9Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.