Skip to content
COOEY

EXPOSURES › CVE-2026-27690

CVE-2026-27690

CRITICAL
DETAIL
SourceNVD · cve Published2026-07-14 CVSS9.1 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-27690 ↗
SHAME 35/100

Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailabl

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.