CVE-2026-66775: Multiple vulnerabilities in SAP Business AI Platform (Approuter)
SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link and trick a victim into following it. Successful exploitation could allow the attacker to bind the victim's session to an attacker-controlled identity, resulting in a low impact on integrity. There is no impact on confidentiality and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66775?
The severity of CVE-2026-66775 is medium, rated at 4.3.
How do I fix CVE-2026-66775?
To fix CVE-2026-66775, configure cross-site request forgery protection in the SAP Approuter settings.
What systems are affected by CVE-2026-66775?
CVE-2026-66775 affects the SAP Business AI Platform, specifically the Approuter component.
What type of vulnerability is CVE-2026-66775?
CVE-2026-66775 is a cross-site request forgery vulnerability that can be exploited by unauthenticated attackers.
What could an attacker achieve by exploiting CVE-2026-66775?
An attacker could potentially bind a victim's session to their own session, allowing unauthorized access to user data.