Junglewise Threat Intelligence

CVE-2026-66776: SAP Approuter session integrity verification bypass

CVE-2026-66776 · Severity: medium · CVSS 5.9 · Published 2026-08-11

Technologies: SAP Approuter. Vendors: SAP.

Executive brief

SAP Approuter, a session management and routing component used in SAP cloud applications, fails to consistently verify the integrity of certain session headers. An attacker with low-level access could craft a malicious request to hijack another user's session if they have previously obtained matching session identifiers through other means. This could allow unauthorized access to sensitive data and operations within SAP applications.

Technical details

The vulnerability is a session integrity verification bypass in SAP Approuter affecting session-related request headers. The root cause is inconsistent enforcement of integrity checks under specific conditions. An attacker must have low privileges and possess out-of-band knowledge of valid session values to exploit this vulnerability. The attack involves sending a specially crafted request that bypasses the integrity check mechanism and loads another user's session context. This requires prior observation of matching session values, increasing the complexity of exploitation. Patches are available through SAP Security Patch Day channels.

Affected products

  • SAP Approuter

Timeline

  • 2026-08-11: disclosed

References