CVE-2026-0487 HIGH

CVE-2026-0487: DLL Hijacking vulnerability in SAProuter on Microsoft Windows

Vendor Sap_Se
Product SAProuter on Microsoft Windows
Weakness CWE-427
Published July 14, 2026
Last update July 20, 2026

CVSS base score

8.4/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system.

Key dates

02Disclosure timeline

July 14, 2026 CVE published
July 20, 2026 Record updated