Junglewise Threat Intelligence

CVE-2026-66775: SAP Approuter CSRF protection bypass in authentication

CVE-2026-66775 · Severity: medium · CVSS 4.3 · Published 2026-08-11

Technologies: SAP Approuter. Vendors: SAP.

Executive brief

SAP Approuter, a critical authentication gateway used in SAP cloud deployments, does not enforce cross-site request forgery (CSRF) protection on its login flow by default. An attacker can craft a malicious link and trick a user into following it, binding the victim's session to an attacker-controlled identity. This could lead to unauthorized access to the victim's SAP applications and data.

Technical details

This is a cross-site request forgery (CSRF) vulnerability in the SAP Approuter authentication flow. The vulnerability exists because CSRF tokens are not enforced by default on the authentication endpoint, allowing unauthenticated attackers to forge requests on behalf of authenticated users. The attack requires user interaction—the victim must click a malicious link or be redirected to a crafted URL. Upon successful exploitation, an attacker can bind the victim's session to an attacker-controlled identity, compromising session integrity. The vulnerability impacts integrity but has no impact on confidentiality or availability. A patch is expected to be available through SAP Security Patch Day processes.

Affected products

  • SAP Approuter

Timeline

  • 2026-08-11: disclosed

References