CVE-2026-66760: Multiple vulnerabilities in SAP Business AI Platform (Approuter)
SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check. This complexity makes the attack difficult to execute. Successful exploitation could allow impersonation of a trusted internal component, resulting in a high impact on integrity and a low impact on confidentiality and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66760?
The severity of CVE-2026-66760 is medium with a score of 6.4.
How can I fix CVE-2026-66760?
To fix CVE-2026-66760, ensure that client certificates are properly validated in all callback flows of the SAP Approuter.
What type of systems are affected by CVE-2026-66760?
CVE-2026-66760 affects the SAP Business AI Platform, specifically the Approuter component.
What are the potential exploits of CVE-2026-66760?
An attacker could exploit CVE-2026-66760 by bypassing the identity check through a valid certificate from the same trusted authority.
Is CVE-2026-66760 easy to exploit?
CVE-2026-66760 is considered difficult to exploit due to the complexity involved in executing the attack.