CVE-2026-66761

SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity.
References
Link Resource
https://me.sap.com/notes/3786038 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:approuter:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-08-11 01:17

Updated : 2026-09-08 20:20


NVD link : CVE-2026-66761

Mitre link : CVE-2026-66761

CVE.ORG link : CVE-2026-66761


JSON object : View

Products Affected

sap

  • approuter
CWE
CWE-770

Allocation of Resources Without Limits or Throttling