CVE-2026-27690: HTTP Request Smuggling in SAP Approuter
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27690?
CVE-2026-27690 has a critical severity rating of 9.1.
How does CVE-2026-27690 impact SAP Approuter?
CVE-2026-27690 allows unauthenticated attackers to exploit HTTP Request Smuggling, potentially exposing user responses and causing system unavailability.
Who is affected by CVE-2026-27690?
Any users or systems utilizing SAP Approuter are at risk due to CVE-2026-27690.
How do I fix CVE-2026-27690?
To remediate CVE-2026-27690, upgrade to the latest patched version of SAP Approuter as provided by SAP.
What is the risk associated with CVE-2026-27690?
The risk associated with CVE-2026-27690 is rated at 66, indicating a significant security threat.