CVE-2026-66778

Summary

SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability.

Affected Software

VendorProductVersion RangeStatus
SAP_SESAP Business AI Platform (Approuter)SAP Approuter node.js package < 23.0.0affected

Weaknesses

  • CWE-644: CWE-644: Improper Neutralization of HTTP Headers for Scripting Syntax

References