Advisory
A note with CVSS 9.1 for component BC-XS-APR was released by SAP on 14.07.2026. The correction/advisory 3720138 was described with "3720138 - [CVE-2026-27690] HTTP Request Smuggling in SAP Approuter" and affects the system type SAP Approuter.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process.
The vulnerability addressed is http request smuggling within SAP Approuter.
Risk specification
SAP Approuter allows an unauthenticated attacker to send a specially crafted HTTP request that causes request-response desynchronization, potentially resulting in the exposure of user responses and system unavailability.
Solution
The updated SAP Approuter version automatically sets DISABLE_CONNECTION_REUSE to TRUE when running in non-Cloud Foundry environments, preventing request-response desynchronization.
