{"api_version":"1","generated_at":"2026-07-21T05:58:29+00:00","cve":"CVE-2026-0487","urls":{"html":"https://cve.report/CVE-2026-0487","api":"https://cve.report/api/cve/CVE-2026-0487.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-0487","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-0487"},"summary":{"title":"DLL Hijacking vulnerability in SAProuter on Microsoft Windows","description":"SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system.","state":"PUBLISHED","assigner":"sap","published_at":"2026-07-14 01:16:16","updated_at":"2026-07-20 16:16:53"},"problem_types":["CWE-427","CWE-427 CWE-427: Uncontrolled Search Path Element"],"metrics":[{"version":"3.1","source":"cna@sap.com","type":"Secondary","score":"8.4","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"8.4","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":8.4,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://me.sap.com/notes/3692165","name":"https://me.sap.com/notes/3692165","refsource":"cna@sap.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://url.sap/sapsecuritypatchday","name":"https://url.sap/sapsecuritypatchday","refsource":"cna@sap.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/piuppi/Proof-of-Concepts/blob/main/SAP/CVE-2026-0487.md","name":"https://github.com/piuppi/Proof-of-Concepts/blob/main/SAP/CVE-2026-0487.md","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-0487","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0487","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"SAP_SE","product":"SAProuter on Microsoft Windows","version":"affected KRNL64NUC 7.22","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAProuter on Microsoft Windows","version":"affected 7.22EXT","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAProuter on Microsoft Windows","version":"affected KRNL64UC 7.22","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAProuter on Microsoft Windows","version":"affected 7.53","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAProuter on Microsoft Windows","version":"affected SAP_ROUTER 7.53","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAProuter on Microsoft Windows","version":"affected 7.54","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAProuter on Microsoft Windows","version":"affected KERNEL 7.22","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAProuter on Microsoft Windows","version":"affected 7.77","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAProuter on Microsoft Windows","version":"affected 7.89","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAProuter on Microsoft Windows","version":"affected 7.93","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAProuter on Microsoft Windows","version":"affected 9.16","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAProuter on Microsoft Windows","version":"affected 9.17","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAProuter on Microsoft Windows","version":"affected 9.18","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"487","cve":"CVE-2026-0487","epss":"0.001480000","percentile":"0.044260000","score_date":"2026-07-20","updated_at":"2026-07-21 00:13:13"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-0487","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-07-14T12:39:52.767116Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-07-14T12:40:00.804Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"},{"providerMetadata":{"dateUpdated":"2026-07-20T14:39:04.209Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"https://github.com/piuppi/Proof-of-Concepts/blob/main/SAP/CVE-2026-0487.md"}],"title":"CVE Program Container","x_generator":{"engine":"ADPogram 0.0.1"}}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"SAProuter on Microsoft Windows","vendor":"SAP_SE","versions":[{"status":"affected","version":"KRNL64NUC 7.22"},{"status":"affected","version":"7.22EXT"},{"status":"affected","version":"KRNL64UC 7.22"},{"status":"affected","version":"7.53"},{"status":"affected","version":"SAP_ROUTER 7.53"},{"status":"affected","version":"7.54"},{"status":"affected","version":"KERNEL 7.22"},{"status":"affected","version":"7.77"},{"status":"affected","version":"7.89"},{"status":"affected","version":"7.93"},{"status":"affected","version":"9.16"},{"status":"affected","version":"9.17"},{"status":"affected","version":"9.18"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system.</p>"}],"value":"SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":8.4,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-427","description":"CWE-427: Uncontrolled Search Path Element","lang":"eng","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-14T00:17:37.478Z","orgId":"e4686d1a-f260-4930-ac4c-2f5c992778dd","shortName":"sap"},"references":[{"url":"https://me.sap.com/notes/3692165"},{"url":"https://url.sap/sapsecuritypatchday"}],"source":{"discovery":"UNKNOWN"},"title":"DLL Hijacking vulnerability in SAProuter on Microsoft Windows","x_generator":{"engine":"Vulnogram 1.0.2"}}},"cveMetadata":{"assignerOrgId":"e4686d1a-f260-4930-ac4c-2f5c992778dd","assignerShortName":"sap","cveId":"CVE-2026-0487","datePublished":"2026-07-14T00:17:37.478Z","dateReserved":"2025-12-09T22:06:31.239Z","dateUpdated":"2026-07-20T14:39:04.209Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-14 01:16:16","lastModifiedDate":"2026-07-20 16:16:53","problem_types":["CWE-427","CWE-427 CWE-427: Uncontrolled Search Path Element"],"metrics":{"cvssMetricV31":[{"source":"cna@sap.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-14T12:39:52.767116Z","id":"CVE-2026-0487","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"487","Ordinal":"1","Title":"DLL Hijacking vulnerability in SAProuter on Microsoft Windows","CVE":"CVE-2026-0487","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"487","Ordinal":"1","NoteData":"SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system.","Type":"Description","Title":"DLL Hijacking vulnerability in SAProuter on Microsoft Windows"}]}}}