CVE-2026-66761: SAP Approuter

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity.

Affected products

  • SAP Approuter: before 23.0.0 (fixed in 23.0.0)

Published 2026-08-11. Last modified 2026-09-08.