Sceawere
Vulnerability Detail
CVE-2026-66775UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SAP Approuter CSRF Authentication Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- SAP_SE
- Product
- SAP Business AI Platform (Approuter)
- Attack Type
- CWE-352: Cross-Site Request Forgery
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link and trick a victim into following it. Successful exploitation could allow the attacker to bind the victim's session to an attacker-controlled identity, resulting in a low impact on integrity. There is no impact on confidentiality and availability.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-08-11T01:17:23.917Z",
"pubdate": "2026-08-11T01:17:23.917Z",
"executiveSummary": "SAP Approuter contains a cross-site request forgery vulnerability due to the default lack of enforcement of cross-site request forgery protection mechanisms during the authentication flow.\nThe primary impact of this vulnerability is a low violation of integrity, allowing an attacker to bind a victim's active session to an attacker-controlled identity.\nThere is no reported impact on confidentiality or system availability resulting from the successful exploitation of this flaw.\nThe affected product is SAP Approuter, which fails to secure the authentication sequence against unauthorized cross-site command execution by default.\nThe risk implication centers on session hijacking and identity spoofing within the context of the application session.\nAn unauthenticated attacker possesses the necessary capabilities to launch this attack by leveraging standard web vectors.\nExploitation requirements dictate that the attacker must craft a malicious link and successfully trick an authenticated or target victim into following or interacting with the crafted URL.",
"technicalDetails": "The root cause of the vulnerability resides in the default configuration and logic of SAP Approuter, which omits cross-site request forgery protection measures specifically within the authentication flow.\nThe vulnerable component is the authentication routing mechanism handling incoming requests and session establishment within SAP Approuter.\nThe vulnerability requires no prior authentication or elevated privileges, allowing any unauthenticated external entity to initiate the attack sequence.\nThe attack vector is network-based, relying on web browsing vectors where a victim interacts with malicious content.\nThe attack flow proceeds as follows: First, the unauthenticated attacker crafts a malicious link designed to interact with the vulnerable authentication flow of SAP Approuter. Second, the attacker induces a victim to follow the malicious link through social engineering or other web-based delivery methods. Third, upon following the link, the victim's browser executes the forged request against the target application. Fourth, due to the absence of robust cross-site request forgery validation in the authentication flow, SAP Approuter processes the request. Finally, the exploitation succeeds as the victim's application session becomes cryptographically or logically bound to the attacker-controlled identity, subverting the expected session association integrity."
}