What is CVE-2026-66777?
CVE-2026-66777 is a vulnerability in SAP Approuter where it fails to sufficiently validate certain incoming requests before forwarding them to backend destinations. Under complex conditions, a low-privileged attacker could send crafted requests to bypass authorization checks and access protected resources. Users of SAP Approuter should urgently apply the relevant security patches.
Azərbaycanca: CVE-2026-66777 SAP Approuter-da gələn sorğuların backend istiqamətlərinə yönləndirilmədən əvvəl kifayət qədər validasiya edilməməsi zəifliyidir. Kompleks şərtlər altında aşağı səlahiyyətli hücumçu xüsusi hazırlanmış sorğular göndərərək avtorizasiya yoxlamalarından yan keçə və qorunan resurslara çata bilər. SAP Approuter istifadəçiləri təcili olaraq təhlükəsizlik yamalarını tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: SAP
FAQ2
What functionality of SAP Approuter is affected by CVE-2026-66777?
CVE-2026-66777 is a vulnerability in SAP Approuter where it fails to sufficiently validate certain incoming requests before forwarding them to backend destinations.
What level of privileges does an attacker need to exploit CVE-2026-66777?
Under complex conditions, a low-privileged attacker could exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.