VYPR
Unrated severityNVD Advisory· Published Jul 14, 2026· Updated Jul 14, 2026

Open Redirect vulnerability in SAP Approuter

CVE-2026-44745

Description

SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.