CVE-2026-66766

7.5

SAP SE · SAP S/4HANA (Manage Supply Protection)

SAP S/4HANA (Private Cloud) utilizes a third-party component susceptible to a Regular Expression Denial of Service (ReDoS) vulnerability, potentially impacting service availability.

Executive summary

A Regular Expression Denial of Service vulnerability in the SAP S/4HANA Manage Supply Protection component could allow an unauthenticated attacker to cause significant service disruption.

Vulnerability

This vulnerability involves an inefficient regular expression complexity within a third-party component. An unauthenticated attacker can trigger this flaw by submitting specifically crafted input, leading to excessive resource consumption and a Denial of Service.

Business impact

The CVSS score of 7.5 indicates a high severity risk. Successful exploitation results in the exhaustion of system resources, causing the application to become unresponsive for legitimate users. This downtime can disrupt critical supply chain management workflows, leading to operational delays and potential loss of productivity.

Remediation

Immediate Action: Apply the vendor security updates immediately as provided in SAP Security Note 3771065.

Proactive Monitoring: Monitor server CPU and memory utilization patterns for sudden, unexplained spikes that may indicate exploitation attempts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to inspect and block malformed or overly complex input strings that match known ReDoS attack patterns.

Exploitation status

Public Exploit Available: No (there is no confirmed public exploit in the available data).

Analyst recommendation

Given the potential for service interruption, organizations should prioritize the installation of the official SAP patch. Failure to address this vulnerability leaves the S/4HANA environment exposed to resource exhaustion attacks that can halt core business operations.

More SAP SE CVEs