CVE-2026-27690
Summary
An HTTP request and response smuggling flaw in the SAP Approuter, scored CVSS 9.1 and patched in SAP's July 2026 security updates.
Details
Approuter is the entry point that fronts many SAP Fiori and business-technology-platform deployments, which is what makes a smuggling flaw there more than a protocol curiosity: where a front-end proxy and a back-end service disagree about message boundaries, an attacker can smuggle a request that the proxy never inspects while the back end acts on it. The digest recorded it as one of two critical flaws in the same patch set — the headline item being a CVSS 9.9 out-of-bounds write in NetWeaver AS ABAP (CVE-2026-44747). Both are patched; Approuter updates are frequently deferred because the component is treated as plumbing rather than as an application, so it is worth checking that the July set went in.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-27690 |
| CVSS | 9.1 |
| Vendor / product | SAP (Approuter) |
| Reported in the digest | 2026-07-15 |
Related Pages
Sources: raw/digests/Cyber-Digest-2026-07-15.md