CVE-2026-66766: SAP SE SAP s/4hana Manage Supply Protection
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful exploitation could exhaust system resources and make the service unavailable, resulting in a high impact on availability. There is no impact on confidentiality and integrity.
Affected products
- SAP SE SAP s/4hana Manage Supply Protection: version 900 only
Published 2026-08-25. Last modified 2026-08-26.