CVE-2026-27690

Summary

Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.

Affected Software

VendorProductVersion RangeStatus
SAP_SESAP ApprouterSAP Approuter node.js package < 20.10.0affected

Weaknesses

  • CWE-444: CWE-444: Inconsistent Interpretation of HTTP Requests

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References