CVE-2026-66773: SAP SE Odata

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data into the application, which may leads to a high impact on confidentiality and low impact on integrity and no impact on Availability.

Affected products

Published 2026-08-11. Last modified 2026-08-26.