Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-23 · updated: 2026-09-23 · tags: [cve] · confidence: high · severity: critical · affected_sectors: [technology, finance, government] · au_impact: false

CVE-2026-27690

Summary

An HTTP request and response smuggling flaw in the SAP Approuter, scored CVSS 9.1 and patched in SAP's July 2026 security updates.

Details

Approuter is the entry point that fronts many SAP Fiori and business-technology-platform deployments, which is what makes a smuggling flaw there more than a protocol curiosity: where a front-end proxy and a back-end service disagree about message boundaries, an attacker can smuggle a request that the proxy never inspects while the back end acts on it. The digest recorded it as one of two critical flaws in the same patch set — the headline item being a CVSS 9.9 out-of-bounds write in NetWeaver AS ABAP (CVE-2026-44747). Both are patched; Approuter updates are frequently deferred because the component is treated as plumbing rather than as an application, so it is worth checking that the July set went in.

Attribute Detail
CVE CVE-2026-27690
CVSS 9.1
Vendor / product SAP (Approuter)
Reported in the digest 2026-07-15

Related Pages

Sources: raw/digests/Cyber-Digest-2026-07-15.md