CVE-2026-66776: Multiple vulnerabilities in SAP Business AI Platform (Approuter)
SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute. This could result in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66776?
The severity of CVE-2026-66776 is medium with a CVSS score of 5.9.
How do I fix CVE-2026-66776?
To fix CVE-2026-66776, ensure that you apply the latest security patches provided by SAP for the Business AI Platform.
What impact does CVE-2026-66776 have?
CVE-2026-66776 allows an attacker with low privileges to potentially load another user's session context due to insufficient integrity verification.
Who is affected by CVE-2026-66776?
CVE-2026-66776 affects users of the SAP Business AI Platform, specifically those utilizing the Approuter component.
When was CVE-2026-66776 published?
CVE-2026-66776 was published on August 11, 2026.