Medium severity4.3NVD Advisory· Published Aug 11, 2026· Updated Sep 8, 2026
CVE-2026-66775
CVE-2026-66775
Description
SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link and trick a victim into following it. Successful exploitation could allow the attacker to bind the victim's session to an attacker-controlled identity, resulting in a low impact on integrity. There is no impact on confidentiality and availability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- url.sap/sapsecuritypatchdaynvdVendor Advisory
- me.sap.com/notes/3786038nvdPermissions Required
News mentions
1- SAP: 25 Vulnerabilities Disclosed, Critical Commerce Cloud Flaw Actively ExploitedVypr Intelligence · Aug 11, 2026