SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful exploitation could exhaust system resources and make the service unavailable, resulting in a high impact on availability. There is no impact on confidentiality and integrity.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-25 01:16
Updated : 2026-08-26 19:00
NVD link : CVE-2026-66766
Mitre link : CVE-2026-66766
CVE.ORG link : CVE-2026-66766
JSON object : View
Products Affected
No product.
CWE
CWE-1333
Inefficient Regular Expression Complexity
