Medium severity5.9NVD Advisory· Published Aug 11, 2026· Updated Sep 8, 2026
CVE-2026-66776
CVE-2026-66776
Description
SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute. This could result in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- url.sap/sapsecuritypatchdaynvdVendor Advisory
- me.sap.com/notes/3786038nvdPermissions Required
News mentions
1- SAP: 25 Vulnerabilities Disclosed, Critical Commerce Cloud Flaw Actively ExploitedVypr Intelligence · Aug 11, 2026