Description
SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on conditions outside the attacker's control. This could result in a low impact on availability. There is no impact on confidentiality and integrity.
Published: 2026-08-11
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from inconsistent error handling in SAP Approuter, classified as an Improper Handling of Exceptions (CWE-754). An attacker with only low privileges can potentially trigger exploitation if the system is configured non‑normally. Successful exploitation is highly complex because it relies on external conditions beyond the attacker’s control and would only degrade service availability; confidentiality and integrity remain unaffected.

Affected Systems

Affected systems are those running SAP Business AI Platform with the Approuter component, as cataloged under SAP SE. No specific product versions are listed in the advisory, so any installation that uses a non‑default startup configuration potentially remains vulnerable until patched.

Risk and Exploitability

The CVSS score is 3.7 indicating low severity. EPSS data is not available and the vulnerability is not in the CISA KEV list. Given the required context, the attack vector likely needs low‑privilege access to the Approuter and depends on configuration quirks. Because the conditions for successful exploitation are complex and externally influenced, the overall risk to the environment is low, yet monitoring for degraded availability is recommended.

Generated by OpenCVE AI on August 11, 2026 at 01:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest SAP Business AI Platform release that includes the fix for SAP Approuter error handling inconsistencies.
  • Review and adjust the Approuter configuration to enforce default, consistent error handling paths and remove any custom error handlers that might introduce variability.
  • Monitor Approuter logs and availability metrics for unexpected error responses and address any patterns that emerge promptly.

Generated by OpenCVE AI on August 11, 2026 at 01:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap Business Ai Platform (approuter)
Vendors & Products Sap Se
Sap Se sap Business Ai Platform (approuter)

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on conditions outside the attacker's control. This could result in a low impact on availability. There is no impact on confidentiality and integrity.
Title Multiple vulnerabilities in SAP Business AI Platform (Approuter)
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Sap Se Sap Business Ai Platform (approuter)
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T14:27:42.485Z

Reserved: 2026-07-27T17:33:56.949Z

Link: CVE-2026-66774

cve-icon Vulnrichment

Updated: 2026-08-11T14:27:37.962Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T01:17:23.787

Modified: 2026-08-26T19:00:14.450

Link: CVE-2026-66774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:20:32Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions