Description
SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system.
Published: 2026-07-14
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAProuter on Microsoft Windows is vulnerable to DLL hijacking. An unauthenticated attacker can place a malicious DLL in an untrusted location that SAProuter will load, allowing arbitrary code execution and giving the attacker full control over the affected system. This would compromise the confidentiality, integrity, and availability of the host.

Affected Systems

All deployments of SAProuter on Microsoft Windows are affected, as the flaw exists in any installed instance; specific version information has not been disclosed by the CNA at this time.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity vulnerability, while the EPSS score of <1% shows a very low but nonzero likelihood of exploitation. The issue is not cataloged in CISA KEV. Because the attack does not require authentication or elevated privileges, the compromise can occur as soon as an attacker can write a DLL to a directory that SAProuter scans, making it a serious risk for exposed installations.

Generated by OpenCVE AI on July 31, 2026 at 10:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAProuter patch published in SAP Note 3692165 to correct the file‑system permissions that allow untrusted DLLs to be loaded.
  • Limit SAProuter’s network exposure by configuring firewall rules to allow connections only from trusted internal IP ranges, thereby reducing the attack surface.
  • Use Windows AppLocker or a similar application whitelisting solution to block execution of DLLs from directories that are not explicitly authorized.

Generated by OpenCVE AI on July 31, 2026 at 10:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se saprouter On Microsoft Windows
Vendors & Products Sap Se
Sap Se saprouter On Microsoft Windows

Tue, 14 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system.
Title DLL Hijacking vulnerability in SAProuter on Microsoft Windows
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Sap Se Saprouter On Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-07-20T14:39:04.209Z

Reserved: 2025-12-09T22:06:31.239Z

Link: CVE-2026-0487

cve-icon Vulnrichment

Updated: 2026-07-20T14:39:04.209Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:00:06Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element