CVE-2026-66774

Summary

SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on conditions outside the attacker's control. This could result in a low impact on availability. There is no impact on confidentiality and integrity.

Affected Software

VendorProductVersion RangeStatus
SAP_SESAP Business AI Platform (Approuter)SAP Approuter node.js package < 23.0.0affected

Weaknesses

  • CWE-754: CWE-754: Improper Check for Unusual or Exceptional Conditions

References