What is CVE-2026-66775?
CVE-2026-66775 is a vulnerability in SAP Approuter where cross-site request forgery (CSRF) protection is not enforced on the authentication flow by default. An unauthenticated attacker could trick a victim into clicking a malicious link to bind the victim's session to an attacker-controlled one. Users should apply the necessary security updates provided by SAP.
Azərbaycanca: CVE-2026-66775, SAP Approuter-da standart olaraq autentifikasiya axınında cross-site request forgery (CSRF) qorumasının tətbiq edilməməsi zəifliyidir. Bu, autentifikasiya olunmamış hücumçuya zərərli link hazırlayaraq qurbanı aldadıb onun sessiyasını ələ keçirməyə imkan verə bilər. İstifadəçilər SAP tərəfindən təqdim olunan təhlükəsizlik yeniləmələrini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
What security flaw causes the CVE-2026-66775 vulnerability in SAP Approuter?
The vulnerability arises from the fact that cross-site request forgery (CSRF) protection is not enforced on the authentication flow by default.
What can an unauthenticated attacker do by exploiting CVE-2026-66775?
An unauthenticated attacker could trick a victim into clicking a malicious link to bind the victim's session to an attacker-controlled one.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.