high2026-09-08SAP S/4HANA — Manage Supply ProtectionCVE-2026-66766
Regular Expression Denial of Service in Supply Protection
SAP S/4HANA
Our Take
ReDoS at CVSS 7.5 reflects DoS-only impact — no data exposure, no auth bypass. The Supply Protection app is used in MRP-driven manufacturing and retail environments. If it's business-critical for you, treat this as higher priority. Otherwise, next maintenance window is fine.
Vulnerability Detail
Regular Expression Denial of Service (ReDoS) via a vulnerable third-party component in the Manage Supply Protection app. Crafted input triggers catastrophic regex backtracking, causing service unavailability.
Patch Action
Apply the patch per SAP Note 3485073. Verify affected S/4HANA release in the official SAP Note.
Patch Info