
CVE-2026-66775 SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link a… https://www.cve.org/CVERecord?id=CVE-2026-66775
Post summary
The note discloses that CVE‑2026‑66775 in SAP Approuter leaves the authentication flow vulnerable to CSRF, enabling unauthenticated attackers to create malicious links, but provides no PoC, exploit code, active attack evidence, or patch details.

