CVE-2026-66774: Multiple vulnerabilities in SAP Business AI Platform (Approuter)
SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on conditions outside the attacker's control. This could result in a low impact on availability. There is no impact on confidentiality and integrity.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66774?
The severity of CVE-2026-66774 is classified as low with a score of 3.7.
Who is affected by CVE-2026-66774?
CVE-2026-66774 affects users of the SAP Business AI Platform (Approuter) with non-default configurations.
How do I fix CVE-2026-66774?
To fix CVE-2026-66774, ensure that your SAP Business AI Platform (Approuter) is updated to the latest security patch.
What is the potential impact of CVE-2026-66774?
The potential impact of CVE-2026-66774 is low, primarily affecting availability due to complex exploitation conditions.
What conditions are necessary for exploiting CVE-2026-66774?
Exploitation of CVE-2026-66774 requires specific conditions that are outside the attacker's control, making it highly complex.