6.4
CVE-2026-66760
- EPSS 0.12%
- Veröffentlicht 11.08.2026 00:17:28
- Zuletzt bearbeitet 08.09.2026 20:22:13
- Erkennungen
Multiple vulnerabilities in SAP Business AI Platform (Approuter)
SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check. This complexity makes the attack difficult to execute. Successful exploitation could allow impersonation of a trusted internal component, resulting in a high impact on integrity and a low impact on confidentiality and availability.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.021 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| SAP | 6.4 | 1.6 | 4.7 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
https://url.sap/sapsecuritypatchday
https://me.sap.com/notes/3786038