high2026-09-08SAP S/4HANA — Manage Supply ProtectionCVE-2026-66766

Regular Expression Denial of Service in Supply Protection

SAP S/4HANA

Our Take

ReDoS at CVSS 7.5 reflects DoS-only impact — no data exposure, no auth bypass. The Supply Protection app is used in MRP-driven manufacturing and retail environments. If it's business-critical for you, treat this as higher priority. Otherwise, next maintenance window is fine.

Vulnerability Detail

Regular Expression Denial of Service (ReDoS) via a vulnerable third-party component in the Manage Supply Protection app. Crafted input triggers catastrophic regex backtracking, causing service unavailability.

Patch Action

Apply the patch per SAP Note 3485073. Verify affected S/4HANA release in the official SAP Note.

Patch Info

CVSS Score

7.5

SAP Note

3485073

CVE

CVE-2026-66766

Published

2026-09-08

← All patches