SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful exploitation could exhaust system resources and make the service unavailable, resulting in a high impact on availability. There is no impact on confidentiality and integrity.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Aug 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful exploitation could exhaust system resources and make the service unavailable, resulting in a high impact on availability. There is no impact on confidentiality and integrity. | |
| Title | Denial of Service (DoS) in SAP S/4HANA (Manage Supply Protection) | |
| Weaknesses | CWE-1333 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-08-25T01:08:36.749Z
Reserved: 2026-07-27T17:33:40.733Z
Link: CVE-2026-66766
No data.
Status : Received
Published: 2026-08-25T01:16:37.230
Modified: 2026-08-25T01:16:37.230
Link: CVE-2026-66766
No data.
OpenCVE Enrichment
No data.
Weaknesses