Description
SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity.
Published: 2026-08-11
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists because SAP Approuter does not enforce sufficient flow control in certain functions, allowing an attacker with low privileges to send large volumes of data without receiving responses. This causes unbounded memory growth, leading to a low impact on availability. Confidentiality and integrity are not affected.

Affected Systems

The affected product is SAP Business AI Platform (Approuter) from SAP SE. No specific version information is provided.

Risk and Exploitability

The CVSS score of 4.3 indicates a low to moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower current exploitation likelihood. The attack vector likely involves an attacker who has some level of access to the Approuter to send large data payloads, exploiting the lack of flow control.

Generated by OpenCVE AI on August 11, 2026 at 01:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available SAP patches for SAP Business AI Platform Approuter.
  • Restrict user privileges to prevent low‑privileged users from sending excessive data to the Approuter.
  • Monitor memory usage and enforce limits on request size or flow control.

Generated by OpenCVE AI on August 11, 2026 at 01:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity.
Title Multiple vulnerabilities in SAP Business AI Platform (Approuter)
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T00:17:38.477Z

Reserved: 2026-07-27T17:33:40.733Z

Link: CVE-2026-66761

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T01:30:04Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling