Description
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.
Published: 2026-07-14
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from HTTP request smuggling in SAP Approuter. An unauthenticated attacker can send a specially crafted HTTP request that induces request‑response desynchronization. This can expose user responses, compromising confidentiality, and disrupt normal operation, raising availability concerns.

Affected Systems

SAP Approuter components provided by SAP SE. No specific version range is detailed in the advisory.

Risk and Exploitability

CVSS score of 9.1 indicates very high severity. EPSS < 1% suggests low current exploitation probability. The issue is not listed in CISA KEV, so active exploitation risk depends on the presence of unauthenticated interfaces. The flaw can be exploited over the network via standard HTTP, requiring no authentication.

Generated by OpenCVE AI on July 31, 2026 at 10:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official SAP patch described in SAP Note 3720138.
  • Reconfigure the Approuter to enforce strict RFC‑7230 compliant request parsing and reject ambiguous pipelined requests.
  • Deploy traffic monitoring to detect and alert on suspicious request patterns that could indicate smuggling attempts.

Generated by OpenCVE AI on July 31, 2026 at 10:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap Approuter
Vendors & Products Sap Se
Sap Se sap Approuter

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.
Title HTTP Request Smuggling in SAP Approuter
Weaknesses CWE-444
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Subscriptions

Sap Se Sap Approuter
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-07-14T12:46:07.535Z

Reserved: 2026-02-23T17:50:17.028Z

Link: CVE-2026-27690

cve-icon Vulnrichment

Updated: 2026-07-14T12:45:45.866Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:00:06Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')