medium2026-08-11SAPCVE-2026-66770
SQL Injection in SAP Application Component CA-EPT-SMI
SAP Application Component (CA-EPT-SMI)
Our Take
SQL injection, authenticated access required. Next planned window.
Vulnerability Detail
SQL injection vulnerability in the CA-EPT-SMI application component of SAP allows an authenticated attacker to inject malicious SQL statements, potentially accessing or modifying data beyond their intended authorisation.
Patch Action
Apply SAP Note 3766473. Verify affected versions and the specific product in the official SAP Note.
Patch Info