Open Redirect vulnerability in SAP Approuter
Published Jul 14, 2026
8.1
HIGHCVSS 3.1
EPSS 0.47%
Description
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.
Affected products
-
Affected
- SAP Approuter node.js package < 21.2.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| SAP SE | SAP Approuter | unaffected | Affected
|
No data.
No Red Hat product state for this CVE.
@sap/approuter
npm
Introduced 0 Fixed 21.2.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @sap/approuter | 0 | 21.2.0 |
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43585 Advisory
- https://github.com/advisories/GHSA-44p5-3m5g-vfhj Advisory
- https://me.sap.com/notes/3741519 Permissions Required
- https://nvd.nist.gov/vuln/detail/CVE-2026-44745
- https://url.sap/sapsecuritypatchday Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43585 | Advisory | |
| https://github.com/advisories/GHSA-44p5-3m5g-vfhj | Advisory | |
| https://me.sap.com/notes/3741519 | Permissions Required | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-44745 | ||
| https://url.sap/sapsecuritypatchday | Vendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub