Junglewise Threat Intelligence

CVE-2026-66774: SAP Approuter error handling denial of service

CVE-2026-66774 · Severity: low · CVSS 3.7 · Published 2026-08-11

Technologies: SAP Approuter. Vendors: SAP.

Executive brief

SAP Approuter, a critical routing and authentication component in SAP cloud environments, does not consistently handle certain error conditions. An attacker with low privileges could exploit this vulnerability under specific non-default configurations to cause a service disruption. Exploitation is complex and depends on factors outside the attacker's control, resulting in limited availability impact with no effect on data confidentiality or integrity.

Technical details

The vulnerability exists in SAP Approuter's error handling logic, where certain error conditions are not processed consistently across all code paths. An attacker with low privileges can trigger these unhandled error states under non-default configuration scenarios. The attack vector requires network access and low-level authentication, but successful exploitation depends on race conditions or environmental factors outside the attacker's direct control. The impact is limited to availability disruption with no compromise of data confidentiality or integrity. SAP has published security note 3786038 and patches are available via their Security Patch Day process.

Affected products

  • SAP Approuter

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: advisory: SAP Security Patch Day

References