Sceawere

Vulnerability Detail

CVE-2026-66775UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SAP Approuter CSRF Authentication Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
4h ago
Vendor
SAP_SE
Product
SAP Business AI Platform (Approuter)
Attack Type
CWE-352: Cross-Site Request Forgery
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link and trick a victim into following it. Successful exploitation could allow the attacker to bind the victim's session to an attacker-controlled identity, resulting in a low impact on integrity. There is no impact on confidentiality and availability.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-11T01:17:23.917Z",
  "pubdate": "2026-08-11T01:17:23.917Z",
  "executiveSummary": "SAP Approuter contains a cross-site request forgery vulnerability due to the default lack of enforcement of cross-site request forgery protection mechanisms during the authentication flow.\nThe primary impact of this vulnerability is a low violation of integrity, allowing an attacker to bind a victim's active session to an attacker-controlled identity.\nThere is no reported impact on confidentiality or system availability resulting from the successful exploitation of this flaw.\nThe affected product is SAP Approuter, which fails to secure the authentication sequence against unauthorized cross-site command execution by default.\nThe risk implication centers on session hijacking and identity spoofing within the context of the application session.\nAn unauthenticated attacker possesses the necessary capabilities to launch this attack by leveraging standard web vectors.\nExploitation requirements dictate that the attacker must craft a malicious link and successfully trick an authenticated or target victim into following or interacting with the crafted URL.",
  "technicalDetails": "The root cause of the vulnerability resides in the default configuration and logic of SAP Approuter, which omits cross-site request forgery protection measures specifically within the authentication flow.\nThe vulnerable component is the authentication routing mechanism handling incoming requests and session establishment within SAP Approuter.\nThe vulnerability requires no prior authentication or elevated privileges, allowing any unauthenticated external entity to initiate the attack sequence.\nThe attack vector is network-based, relying on web browsing vectors where a victim interacts with malicious content.\nThe attack flow proceeds as follows: First, the unauthenticated attacker crafts a malicious link designed to interact with the vulnerable authentication flow of SAP Approuter. Second, the attacker induces a victim to follow the malicious link through social engineering or other web-based delivery methods. Third, upon following the link, the victim's browser executes the forged request against the target application. Fourth, due to the absence of robust cross-site request forgery validation in the authentication flow, SAP Approuter processes the request. Finally, the exploitation succeeds as the victim's application session becomes cryptographically or logically bound to the attacker-controlled identity, subverting the expected session association integrity."
}
CVE-2026-66775: SAP Approuter CSRF Authentication Vulnerability (MEDIUM Severity, CVSS: 4.3) - Sceawere