CVE-2026-66775Disclosure(sap / approuter)

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link and trick a victim into following it. Successful exploitation could allow the attacker to bind the victim's session to an attacker-controlled identity, resulting in a low impact on integrity. There is no impact on confidentiality and availability.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • approuter

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
approuter

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-11: 2Technical Details · 2026-08-11: 208-11
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-66775 SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link a… https://www.cve.org/CVERecord?id=CVE-2026-66775

    Post summary

    The note discloses that CVE‑2026‑66775 in SAP Approuter leaves the authentication flow vulnerable to CSRF, enabling unauthenticated attackers to create malicious links, but provides no PoC, exploit code, active attack evidence, or patch details.

    000101.4K
    57.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-66775 SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link a… https://www.cve.org/CVERecord?id=CVE-2026-66775 ----- Traducción: CVE-2026-66775 SAP… http://infoflow.cloud`

    Post summary

    A new vulnerability, CVE‑2026‑66775, is disclosed affecting SAP Approuter by omitting CSRF protection in its authentication flow, enabling malicious link construction, yet no exploit, patch, or active‑exploitation details are provided.

    0000038
    97 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsapapprouter-node.js-

Explore more