Description
SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability.
Published: 2026-08-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in SAP Approuter's inadequate sanitization of certain request headers that are forwarded to internal components. An unauthenticated attacker can craft a request with malicious header values to obtain limited unauthorized access to information. The impact is a low level breach of confidentiality, with no compromise to integrity or availability reported.

Affected Systems

Vendors and products affected include SAP Business AI Platform (Approuter). Specific versions or version ranges are not disclosed in the available data; administrators should review the referenced SAP notes for detailed version applicability.

Risk and Exploitability

The CVSS score of 5.3 places this issue in the low‑to‑medium risk category. The EPSS score is not available, but the lack of a KEV listing suggests low exploitation activity to date. The attack vector is likely remote, via crafted HTTP requests sent to the Approuter, requiring no authentication. In the absence of existing safeguards, a path exists to extract restricted information from downstream services.

Generated by OpenCVE AI on August 11, 2026 at 01:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch provided in SAP Note 3786038 to address header sanitization in the Approuter.
  • Configure SAP Approuter to enforce strict header validation or a whitelist to reject non‑standard or suspicious header values.
  • Implement network segmentation or firewall rules to restrict inbound traffic to the Approuter only from trusted internal sources.
  • Monitor traffic for anomalous header patterns and audit logs for unauthorized access attempts.

Generated by OpenCVE AI on August 11, 2026 at 01:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap Business Ai Platform (approuter)
Vendors & Products Sap Se
Sap Se sap Business Ai Platform (approuter)

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability.
Title Multiple vulnerabilities in SAP Business AI Platform (Approuter)
Weaknesses CWE-644
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Sap Se Sap Business Ai Platform (approuter)
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T14:26:49.123Z

Reserved: 2026-07-27T17:33:56.949Z

Link: CVE-2026-66778

cve-icon Vulnrichment

Updated: 2026-08-11T14:26:44.652Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T01:17:24.283

Modified: 2026-08-26T19:00:14.450

Link: CVE-2026-66778

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:20:18Z

Weaknesses
  • CWE-644

    Improper Neutralization of HTTP Headers for Scripting Syntax