What is CVE-2026-66761?
SAP Approuter lacks proper flow control in certain functionality, allowing a low-privileged attacker to send high volumes of data without consuming responses, leading to unbounded memory growth. This causes a low impact on availability with no effect on confidentiality or integrity. Users should apply the relevant security patch immediately.
Azərbaycanca: SAP Approuter-in müəyyən funksionallığında kifayət qədər flow control tətbiq edilməməsi aşağı imtiyazlı istifadəçiyə cavabları istehlak etmədən yüksək həcmli məlumat göndərməyə imkan verir. Bu, limitsiz yaddaş artımına və aşağı səviyyəli əlçatanlıq pozuntusuna səbəb olur, məxfilik və bütövlüyə təsir etmir. SAP Approuter istifadəçiləri təhlükəsizlik yamasını tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
What security issue does the lack of flow control in SAP Approuter cause?
This vulnerability allows a low-privileged attacker to send high volumes of data without consuming responses, leading to unbounded memory growth and a low impact on availability.
Does CVE-2026-66761 affect confidentiality or integrity?
No, this vulnerability only causes a low impact on availability, with no effect on confidentiality or integrity.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.