# CVE-2026-66766

## Summary

- **CVE ID:** CVE-2026-66766
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-1333
- **Published:** Aug 25, 2026
- **Last Modified:** Aug 25, 2026

## Description

SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful exploitation could exhaust system resources and make the service unavailable, resulting in a high impact on availability. There is no impact on confidentiality and integrity.

## Affected Products

- SAP_SE — SAP S/4HANA (Manage Supply Protection) (UIS4HOP1 800)
- SAP_SE — SAP S/4HANA (Manage Supply Protection) (900)

## References

- [CNA](https://me.sap.com/notes/3771065)
- [CNA](https://url.sap/sapsecuritypatchday)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.29%
- **EPSS Percentile:** 21.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._