Description
SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute. This could result in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.
Published: 2026-08-11
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP Approuter fails to enforce integrity checks on certain session‐related request headers under specific conditions. An attacker with low privileges can craft a request that bypasses these checks and injects another user’s session context. The compromise primarily threatens confidentiality, allowing the attacker to view data belonging to other users, while the impact on integrity is low and there is no effect on availability.

Affected Systems

The vulnerability affects SAP Business AI Platform (Approuter) from SAP_SE. No specific product version information is provided in the CNA data.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting no current widespread exploitation. Successful exploitation requires an attacker to have a low‑privilege foothold and to have previously observed matching session values out‑of‑band, which makes the attack complex. Based on the description, it is inferred that the attack originates from within the environment where session headers can be monitored, and that it relies on bypassing integrity checks rather than exploiting a direct code execution or denial of service path.

Generated by OpenCVE AI on August 11, 2026 at 01:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify that SAP Approuter is configured to enforce strict validation of all session‑related request headers, and disable any settings that allow integrity checks to be skipped.
  • Apply any SAP security patches or updates that address this session integrity issue as soon as they are released.
  • Monitor Approuter logs for anomalous header modifications or attempts to inject alternate session contexts, and restrict the privilege level of users who can send such requests.

Generated by OpenCVE AI on August 11, 2026 at 01:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap Business Ai Platform (approuter)
Vendors & Products Sap Se
Sap Se sap Business Ai Platform (approuter)

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute. This could result in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.
Title Multiple vulnerabilities in SAP Business AI Platform (Approuter)
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Sap Se Sap Business Ai Platform (approuter)
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T14:27:15.810Z

Reserved: 2026-07-27T17:33:56.949Z

Link: CVE-2026-66776

cve-icon Vulnrichment

Updated: 2026-08-11T14:27:11.373Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T01:17:24.030

Modified: 2026-08-26T19:00:14.450

Link: CVE-2026-66776

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:20:25Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature