CVE-2026-66766: Denial of Service (DoS) in SAP S/4HANA (Manage Supply Protection)
SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful exploitation could exhaust system resources and make the service unavailable, resulting in a high impact on availability. There is no impact on confidentiality and integrity.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker can exploit the issue remotely by supplying specially crafted input to the affected functionality. No privileges or user interaction are required.
What is the expected impact of successful exploitation?
The vulnerable regular expression can cause excessive processing and exhaust system resources, making the affected service unavailable. The provided information indicates no confidentiality or integrity impact.
Which deployment is identified as affected?
The affected product identified in the available information is SAP S/4HANA (Private Cloud), specifically its Manage Supply Protection functionality.