A AegiFlow
HIGHCVSS 8.1EPSS 0.5%

CVE-2026-44745

CVE-2026-44745 updated by NVD

Published
2026-07-14
Modified
2026-09-10
EPSS percentile
39%
Sources
github-advisory, nvd

Summary

SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.

Affected packages

EcosystemPackageAffected versionsFixed versions
npm@sap/approuter21.2.0

Remediation: Upgrade to 21.2.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.