What is CVE-2026-66776?
CVE-2026-66776 is a vulnerability in SAP Approuter where integrity verification on certain session-related request headers is not consistently enforced under specific conditions. This could allow a low-privileged attacker to bypass the check and load another user's session context. It is recommended to immediately apply the security patch provided by SAP to protect affected systems.
Azərbaycanca: CVE-2026-66776 SAP Approuter-in müəyyən şərtlər altında bəzi sessiya ilə bağlı sorğu başlıqlarında bütövlük doğrulamasını ardıcıl tətbiq etməməsi zəifliyidir. Bu, aşağı səlahiyyətli təcavüzkarın digər istifadəçinin sessiyası kontekstini ələ keçirməsinə imkan verə bilər. Təsirə məruz qalmış versiyalardan istifadə edən sistemləri qorumaq üçün SAP tərəfindən təqdim olunan təhlükəsizlik yamasının dərhal tətbiq edilməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What product is affected by CVE-2026-66776 and what is its primary cause?
This vulnerability affects SAP Approuter. The primary cause is that integrity verification on certain session-related request headers is not consistently enforced under specific conditions.
What can an attacker gain by exploiting this vulnerability?
A low-privileged attacker could bypass the integrity verification and load another user's session context.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.