Skip to content
SAPCVE-2026-66776

SAP Business AI Platform (Approuter): improper signature check

Medium5.9CVE-2026-66776 · Published Aug 11, 2026 · updated Sep 8, 2026

SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute. This could result in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.

SAP advisory

Affected versions

PackageAffectedFixed in
SAP Business AI Platform (Approuter)
Product
<= SAP Approuter node.js package < 23.0.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-347

More SAP advisories

All SAP
Advisory
SAP Commerce Cloud (Data Hub Adapter): remote code execution
Critical10.0Aug 11
SAP Business AI Platform (Approuter): path traversal
Medium5.9Aug 11
SAP Approuter does not sufficiently sanitize certain request headers before...
Medium5.3Aug 11
SAP NetWeaver Application Server ABAP: cross-site scripting
Medium6.3Aug 11
SAP BusinessObjects Business Intelligence Platform (Central : hard-coded key
High7.9Aug 11
SAP S/4 HANA (Reprocess Bank Statement Items): privilege escalation
Medium4.3Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.