Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap Se
Sap Se odata |
|
| Vendors & Products |
Sap Se
Sap Se odata |
Tue, 11 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data into the application, which may leads to a high impact on confidentiality and low impact on integrity and no impact on Availability. | |
| Title | Server-controlled `__next` URL is not checking cross-origin | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-08-11T14:27:55.800Z
Reserved: 2026-07-27T17:33:56.949Z
Link: CVE-2026-66773
Updated: 2026-08-11T14:27:51.310Z
Status : Received
Published: 2026-08-11T01:17:23.660
Modified: 2026-08-11T15:17:33.730
Link: CVE-2026-66773
No data.
OpenCVE Enrichment
Updated: 2026-08-11T14:20:34Z