CVE-2026-66777
Last modified
CVE-2026-66777 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the required conditions, an attacker with low privileges could send specially crafted requests to bypass authorization checks and reach protected resources beyond their assigned scope. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the required conditions, an attacker with low privileges could send specially crafted requests to bypass authorization checks and reach protected resources beyond their assigned scope. Successful exploitation could allow the attacker to read sensitive data and perform limited modifications on protected resources, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Approuter | < 23.0.0 |
References
- https://me.sap.com/notes/3786038Permissions Required
- https://url.sap/sapsecuritypatchdayVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-66777?
How severe is CVE-2026-66777?
How do I fix CVE-2026-66777?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-66771SAPUI5 allows a key user with content adaptation privileges …6.1
- CVE-2026-66772SAP BusinessObjects Business Intelligence Platform (Admin To…4.3
- CVE-2026-66773A malicious or compromised OData service could disclose sens…5.9
- CVE-2026-66774SAP Approuter does not consistently handle certain error con…3.7
- CVE-2026-66775SAP Approuter does not enforce cross-site request forgery pr…4.3
- CVE-2026-66776SAP Approuter does not consistently enforce integrity verifi…5.9
- CVE-2026-66778SAP Approuter does not sufficiently sanitize certain request…5.3
- CVE-2026-66779Due to a Cross-Site Scripting (XSS) vulnerability in SAP Net…6.3
- CVE-2026-6678Integer underflow in wc_PKCS7_DecryptOri when handling craft…5.3
- CVE-2026-66780A flaw was found in the submariner-operator component. The `…6.5
- CVE-2026-66781A flaw was found in the Submariner operator. The Submariner …5.4
- CVE-2026-66782A flaw was found in the Submariner operator. This vulnerabil…5.8
Are you affected by CVE-2026-66777?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
