Every CVE whose affected-product data names Sap Approuter, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (13)
CVE-2026-27690 — CVSS 9.1 (critical): Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request…
CVE-2026-44745 — CVSS 8.1 (high): SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an…
CVE-2026-58230 — CVSS 7.0 (high): SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a…
CVE-2026-66760 — CVSS 6.4 (medium): SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a…
CVE-2026-66776 — CVSS 5.9 (medium): SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An…
CVE-2026-58238 — CVSS 5.9 (medium): SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially…
CVE-2026-58237 — CVSS 5.9 (medium): WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could…
CVE-2026-66777 — CVSS 5.9 (medium): SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the…
CVE-2026-66778 — CVSS 5.3 (medium): SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated…
CVE-2026-66775 — CVSS 4.3 (medium): SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker…
CVE-2026-66761 — CVSS 4.3 (medium): SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of…
CVE-2026-66774 — CVSS 3.7 (low): SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default…
CVE-2026-58239 — CVSS 3.7 (low): SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted…