High severity8.1NVD Advisory· Published Jul 14, 2026· Updated Sep 8, 2026
CVE-2026-44745
CVE-2026-44745
Description
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@sap/approuternpm | < 21.2.0 | 21.2.0 |
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-44p5-3m5g-vfhjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-44745ghsaADVISORY
- url.sap/sapsecuritypatchdaynvdVendor AdvisoryWEB
- me.sap.com/notes/3741519nvdPermissions RequiredWEB
News mentions
0No linked articles in our index yet.