CVE-2026-44745

HIGH

SAP Approuter < 21.2.0 - Open Redirect in OAuth2 Login Flow

Title source: manual
STIX 2.1

Description

SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.

Scores

CVSS v3 8.1
EPSS 0.0033
EPSS Percentile 25.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-601
Status published
Products (1)
SAP_SE/SAP Approuter SAP Approuter node.js package < 21.2.0
Published Jul 14, 2026
Tracked Since Jul 14, 2026