medium2026-08-11SAPCVE-2026-66770

SQL Injection in SAP Application Component CA-EPT-SMI

SAP Application Component (CA-EPT-SMI)

Our Take

SQL injection, authenticated access required. Next planned window.

Vulnerability Detail

SQL injection vulnerability in the CA-EPT-SMI application component of SAP allows an authenticated attacker to inject malicious SQL statements, potentially accessing or modifying data beyond their intended authorisation.

Patch Action

Apply SAP Note 3766473. Verify affected versions and the specific product in the official SAP Note.

Patch Info

CVSS Score

6.3

SAP Note

3766473

CVE

CVE-2026-66770

Published

2026-08-11

← All patches