CVE-2026-66778: Multiple vulnerabilities in SAP Business AI Platform (Approuter)
SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66778?
CVE-2026-66778 has a medium severity rating of 5.3.
How do I fix CVE-2026-66778?
To fix CVE-2026-66778, ensure that your SAP Business AI Platform (Approuter) is updated to the latest version recommended by SAP.
What can be exploited in CVE-2026-66778?
CVE-2026-66778 can be exploited by an unauthenticated attacker sending specially crafted requests that bypass input validation.
What is the impact of CVE-2026-66778?
The impact of CVE-2026-66778 is low, affecting confidentiality as it allows limited unauthorized access to information.
Is authentication required to exploit CVE-2026-66778?
No, exploitation of CVE-2026-66778 does not require authentication.