Medium severity6.4NVD Advisory· Published Aug 11, 2026· Updated Sep 8, 2026
CVE-2026-66760
CVE-2026-66760
Description
SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check. This complexity makes the attack difficult to execute. Successful exploitation could allow impersonation of a trusted internal component, resulting in a high impact on integrity and a low impact on confidentiality and availability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- url.sap/sapsecuritypatchdaynvdVendor Advisory
- me.sap.com/notes/3786038nvdPermissions Required
News mentions
1- SAP: 25 Vulnerabilities Disclosed, Critical Commerce Cloud Flaw Actively ExploitedVypr Intelligence · Aug 11, 2026