{"id":14595,"date":"2026-08-18T10:38:32","date_gmt":"2026-08-18T08:38:32","guid":{"rendered":"https:\/\/www.inprosec.com\/?p=14595"},"modified":"2026-08-18T10:38:54","modified_gmt":"2026-08-18T08:38:54","slug":"sap-security-notes-august-2026","status":"publish","type":"post","link":"https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/","title":{"rendered":"SAP Security Notes, August 2026"},"content":{"rendered":"<p><b>Through services such as the SAP Security Assessment, Inprosec helps its clients improve the security levels of their SAP systems.<\/b><\/p>\n\n<h2>August 2026 Notes<\/h2>\n<h3>Monthly Summary and Highlights<\/h3>\n<div>\n<div class=\"elementToProof\">This month the total number was <b>31 notes<\/b> (28 new, 1 security notice and 2 updates), 11 more than in July. This month <b>4 Hot News<\/b> were published, the same amount as in the previous period. Regarding high-criticality notes, there are <b>8<\/b>, two more than in July. Medium and low notes will not be reviewed, so we will provide detail on a total of <b>12 notes<\/b> (all those with a CVSS of 7 or higher).<\/div>\n<div><\/div>\n<div class=\"elementToProof\">We have a total of <b>31 notes<\/b> for the whole month (28 new, 1 security notice and 2 updates to notes from previous months).<\/div>\n<div><\/div>\n<div class=\"elementToProof\">We will review in detail a total of 12 notes, all of high criticality and Hot News:<\/div>\n<div><\/div>\n<ol start=\"1\" data-path-to-node=\"9\">\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The highest-criticality note of the month (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ff0000;\"><b>10.0<\/b><\/span>) is a Hot News related to <b>&#8220;Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The second note in criticality (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ff0000;\"><b>9.9<\/b><\/span>) is another Hot News related to <b>&#8220;Code Injection vulnerability in SAP Manufacturing Integration and Intelligence&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The third note in criticality (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ff0000;\"><b>9.8<\/b><\/span>) is another Hot News related to <b>&#8220;Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The fourth note in criticality (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ff0000;\"><b>9.1<\/b><\/span>) is another Hot News related to <b>&#8220;Code Injection vulnerability in Manufacturing Integration and Intelligence&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The sixth note we will review (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>8.8<\/b><\/span>) is of high criticality and concerns <b>&#8220;Privilege Escalation vulnerability in SAP ABAP Developer Tools&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The seventh note we will review (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>8.1<\/b><\/span>) is of high criticality and concerns <b>&#8220;Potential buffer overflow vulnerability affects SAP Commerce Cloud in public\u2011cloud deployments with NGINX&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The eighth note we will review (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7.9<\/b><\/span>) is of high criticality and concerns <b>&#8220;Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server)&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The eighth note we will review (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7.6<\/b><\/span>) is of high criticality and concerns <b>&#8220;Remote Code Execution vulnerability in Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach)&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The ninth note we will review (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7.6<\/b><\/span>) is of high criticality and concerns <b>&#8220;Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The tenth note we will review (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7.3<\/b><\/span>) is of high criticality and concerns <b>&#8220;Missing Authorization Check in SAP Manufacturing Integration and Intelligence&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The eleventh note with the same criticality (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7.3<\/b><\/span>) is of high criticality and concerns <b>&#8220;Missing Authorization Check in SAP Manufacturing Integration and Intelligence&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The twelfth and last note we will review (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7.0<\/b><\/span>) is of high criticality and concerns <b>&#8220;Multiple vulnerabilities in SAP Business AI Platform (Approuter)&#8221;<\/b>.<\/div>\n<\/li>\n<\/ol>\n<div class=\"elementToProof\">This month the most predominant type was <b>&#8220;Missing Authorization Check&#8221;<\/b> (8\/31 on patch day).<\/div>\n<div class=\"elementToProof\">In the chart we can see the classification of August&#8217;s notes, as well as the evolution and classification of the previous 5 months (only Sec. Tuesday \/ Patch Day \u2013 by SAP notes)<\/div>\n<div class=\"elementToProof\">\n<div><\/div>\n<\/div>\n<\/div>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-14596\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/08\/Portada-Notas-SAP-agosto-2026.jpg\" alt=\"\" width=\"700\" height=\"368\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/08\/Portada-Notas-SAP-agosto-2026.jpg 1200w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/08\/Portada-Notas-SAP-agosto-2026-300x158.jpg 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/08\/Portada-Notas-SAP-agosto-2026-1024x538.jpg 1024w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/08\/Portada-Notas-SAP-agosto-2026-600x315.jpg 600w\" sizes=\"(max-width: 700px) 100vw, 700px\" \/><\/p>\n<h2>Full details<\/h2>\n<p class=\"elementToProof\">The <b>full details of the most relevant notes<\/b> are as follows (in English):<\/p>\n<ol>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) (<\/b><a id=\"OWA7f99462f-5ace-d919-0358-17b96d9724f3\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3771065\" href=\"https:\/\/me.sap.com\/notes\/3771065\" data-auth=\"NotApplicable\" data-linkindex=\"0\"><b>3771065<\/b><\/a><b>)<\/b>: SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application. A temporary workaround is available. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ff0000;\"><b>10,0<\/b><\/span><b>\/10 [<\/b><a id=\"OWAff9906ea-26b0-3438-48fc-7cf155f088d2\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-58231\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-58231\" data-auth=\"NotApplicable\" data-linkindex=\"1\"><b>CVE-2026-58231<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Code Injection vulnerability in SAP Manufacturing Integration and Intelligence (<\/b><a id=\"OWA3b702127-0616-2223-8161-38837df1d247\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3765948\" href=\"https:\/\/me.sap.com\/notes\/3765948\" data-auth=\"NotApplicable\" data-linkindex=\"2\"><b>3765948<\/b><\/a><b>)<\/b>: SAP Manufacturing Integration and Intelligence allows a low-privileged attacker to submit specially crafted input that causes the application to retrieve and process attacker-controlled content from an external source. Successful exploitation could enable execution of arbitrary commands on the underlying host and impact resources beyond the vulnerable component, resulting in high impact on confidentiality, integrity and availability. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ff0000;\"><b>9,9<\/b><\/span><b>\/10 [<\/b><a id=\"OWA8395b08d-37b7-6f1d-8a97-4f3f4a5aa5d3\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44772\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44772\" data-auth=\"NotApplicable\" data-linkindex=\"3\"><b>CVE-2026-44772<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform (<\/b><a id=\"OWA76adc169-83ae-559e-4f08-d1d5463ec229\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3714806\" href=\"https:\/\/me.sap.com\/notes\/3714806\" data-auth=\"NotApplicable\" data-linkindex=\"4\"><b>3714806<\/b><\/a><b>)<\/b>: SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could disclose confidential system information or crash the system, potentially having a high impact on the confidentiality, integrity, and availability of the application. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ff0000;\"><b>9,8<\/b><\/span><b>\/10 [<\/b><a id=\"OWAd2602b86-67ee-48c2-9d1c-4bd821468514\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-34265\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-34265\" data-auth=\"NotApplicable\" data-linkindex=\"5\"><b>CVE-2026-34265<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Code Injection vulnerability in Manufacturing Integration and Intelligence (<\/b><a id=\"OWA7b38316f-5e16-8b6a-c8f3-f500579cb8e5\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3758900\" href=\"https:\/\/me.sap.com\/notes\/3758900\" data-auth=\"NotApplicable\" data-linkindex=\"6\"><b>3758900<\/b><\/a><b>)<\/b>: SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability of the application. A temporary workaround is available. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ff0000;\"><b>9,1<\/b><\/span><b>\/10 [<\/b><a id=\"OWA0a9cc14f-97b4-252c-bb12-b45fb7d3f203\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44758\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44758\" data-auth=\"NotApplicable\" data-linkindex=\"7\"><b>CVE-2026-44758<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Privilege Escalation vulnerability in SAP ABAP Developer Tools (<\/b><a id=\"OWA8cb4050e-983b-be64-f569-d417a1e78112\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3772411\" href=\"https:\/\/me.sap.com\/notes\/3772411\" data-auth=\"NotApplicable\" data-linkindex=\"8\"><b>3772411<\/b><\/a><b>)<\/b>: SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality, integrity, and availability. A temporary workaround is available. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>8,8<\/b><\/span><b>\/10 [<\/b><a id=\"OWA404b5b9c-7c38-7ff7-5450-98ff746a98ab\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-58243\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-58243\" data-auth=\"NotApplicable\" data-linkindex=\"9\"><b>CVE-2026-58243<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Potential buffer overflow vulnerability affects SAP Commerce Cloud in public\u2011cloud deployments with NGINX (<\/b><a id=\"OWAc02f8a0e-2ee5-40fc-37af-a27e5f972896\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3773203\" href=\"https:\/\/me.sap.com\/notes\/3773203\" data-auth=\"NotApplicable\" data-linkindex=\"10\"><b>3773203<\/b><\/a><b>)<\/b>: An unauthenticated attacker could send specially crafted requests that could trigger memory corruption in an internal process. Exploitation depends on conditions outside the attacker&#8217;s control, and on systems where standard memory protections are bypassed. Successful exploitation could lead to arbitrary code execution, resulting in high impact on confidentiality integrity and availability. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>8,1<\/b><\/span><b>\/10 [<\/b><a id=\"OWA53442033-91d5-14df-f1ce-61b18e3bfdec\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-42945\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-42945\" data-auth=\"NotApplicable\" data-linkindex=\"11\"><b>CVE-2026-42945<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server) (<\/b><a id=\"OWA53357f47-718a-5fb5-ecbd-37949cf4bbc9\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3756565\" href=\"https:\/\/me.sap.com\/notes\/3756565\" data-auth=\"NotApplicable\" data-linkindex=\"12\"><b>3756565<\/b><\/a><b>)<\/b>: SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected information, resulting in a high impact on confidentiality and integrity. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7,9<\/b><\/span><b>\/10 [<\/b><a id=\"OWAe55b7947-a063-882a-6fe5-b878378ec8a9\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-66763\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-66763\" data-auth=\"NotApplicable\" data-linkindex=\"13\"><b>CVE-2026-66763<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Remote Code Execution vulnerability in Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach) (<\/b><a id=\"OWA082d9c77-3c1c-35f3-ecf2-141733b53495\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3773304\" href=\"https:\/\/me.sap.com\/notes\/3773304\" rel=\"noopener\" data-auth=\"NotApplicable\" data-hveid=\"0\" data-ved=\"0CAAQ_4QMahgKEwiDlMOLuZ2WAxUAAAAAHQAAAAAQuQI\" data-linkindex=\"14\"><b>3773304<\/b><\/a><b>): <\/b>Enhanced Change and Transport System (CTS+) attach tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application\u2019s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim to process the malicious archive, enabling the attacker to execute the RCE and extract sensitive information and gain control over the system and its processes. This vulnerability has a high impact on confidentiality and integrity of the data, with a low impact on the availability of the system.<b>\u00a0CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7,6<\/b><\/span><b>\/10 [<\/b><a id=\"OWAd261fff9-8f6e-9eda-6783-d87c44beb33e\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-58233\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-58233\" data-auth=\"NotApplicable\" data-linkindex=\"15\"><b>CVE-2026-58233<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence (<\/b><a id=\"OWAd4ff2db3-1a02-b64a-d071-7d0cc9ea3bfa\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3759854\" href=\"https:\/\/me.sap.com\/notes\/3759854\" data-auth=\"NotApplicable\" data-hveid=\"0\" data-ved=\"0CAAQ_4QMahgKEwiU-_ifupuWAxUAAAAAHQAAAAAQnQI\" data-linkindex=\"16\"><b>3759854<\/b><\/a><b>)<\/b>: SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker\u2019s control. Successful exploitation could allow files to be written outside the intended directory and affect other components, resulting in a high impact on confidentiality, integrity, and availability. A temporary workaround is available. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7,6<\/b><\/span><b>\/10 [<\/b><a id=\"OWA27536764-8f97-87e1-8fdd-e2faf7e41885\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44763\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44763\" data-auth=\"NotApplicable\" data-linkindex=\"17\"><b>CVE-2026-44763<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Missing Authorization Check in SAP Manufacturing Integration and Intelligence (<\/b><a id=\"OWA60796792-0605-ce51-cac9-d9acab23e8d0\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3758657\" href=\"https:\/\/me.sap.com\/notes\/3758657\" data-auth=\"NotApplicable\" data-linkindex=\"18\"><b>3758657<\/b><\/a><b>)<\/b>: Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the attacker to retrieve, create, modify, or delete application-managed scheduling data, causing a low impact on confidentiality, integrity, and availability. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7,3<\/b><\/span><b>\/10 [<\/b><a id=\"OWAa53fab80-b3f4-5c2d-306a-d48ad3bc7ac8\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44765\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44765\" data-auth=\"NotApplicable\" data-linkindex=\"19\"><b>CVE-2026-44765<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Missing Authorization Check in SAP Manufacturing Integration and Intelligence (<\/b><a id=\"OWA067f2ee0-a2a7-c555-3641-e6093605d89e\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3758910\" href=\"https:\/\/me.sap.com\/notes\/3758910\" data-auth=\"NotApplicable\" data-linkindex=\"20\"><b>3758910<\/b><\/a><b>)<\/b>: Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed business data, resulting in a limited impact on the confidentiality, integrity, and availability of the affected system. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7,3<\/b><\/span><b>\/10 [<\/b><a id=\"OWA6094c78c-201e-6683-7448-823ae17c9165\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44764\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44764\" data-auth=\"NotApplicable\" data-linkindex=\"21\"><b>CVE-2026-44764<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Multiple vulnerabilities in SAP Business AI Platform (Approuter) (<\/b><a id=\"OWA5cfe6ac1-34bc-f99f-1977-2e4e3ded49cb\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3786038\" href=\"https:\/\/me.sap.com\/notes\/3786038\" data-auth=\"NotApplicable\" data-hveid=\"0\" data-ved=\"0CAAQ_4QMahgKEwiU-_ifupuWAxUAAAAAHQAAAAAQowI\" data-linkindex=\"22\"><b>3786038<\/b><\/a><b>)<\/b>: This SAP security note addresses several vulnerabilities identified in SAP Approuter. The most critical is an Information Disclosure vulnerability where an unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination, resulting in a high impact on confidentiality and a low impact on integrity and availability. A temporary workaround is available. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7,0<\/b><\/span><b>\/10 [<\/b><a id=\"OWA52e34c27-9cf7-be1d-8f1d-9b14f0149226\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-58230\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-58230\" data-auth=\"NotApplicable\" data-linkindex=\"23\"><b>CVE-2026-58230<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p><strong style=\"color: #014888; font-family: inherit; font-size: 1.6rem; letter-spacing: 0em;\">Reference links<\/strong><\/p>\n<div class=\"elementToProof\">\n<p>References, in English, from SAP and Onapsis:<\/p>\n<ul>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><a id=\"OWA03717ebc-24ce-964d-70b2-9c404a704de7\" class=\"OWAAutoLink\" title=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/august-2026.html?isu_page=1\" href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/august-2026.html?isu_page=1\" data-auth=\"NotApplicable\" data-linkindex=\"24\">SAP Security Patch Day &#8211; August 2026<\/a><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><a id=\"OWA47e8033d-cebb-10f9-8067-d071b99b8348\" class=\"OWAAutoLink\" title=\"https:\/\/onapsis.com\/blog\/sap-security-patch-day-august-2026\/?_gl=1*1ee5nn6*_up*MQ..*_ga*MjU5ODE0MDg4LjE3ODY2MTkxNzI.*_ga_2HEPRR6DH5*czE3ODY2MTkxNzIkbzEkZzEkdDE3ODY2MTkxNzYkajU2JGwwJGgxNTI3NjExOTYy\" href=\"https:\/\/onapsis.com\/blog\/sap-security-patch-day-august-2026\/?_gl=1*1ee5nn6*_up*MQ..*_ga*MjU5ODE0MDg4LjE3ODY2MTkxNzI.*_ga_2HEPRR6DH5*czE3ODY2MTkxNzIkbzEkZzEkdDE3ODY2MTkxNzYkajU2JGwwJGgxNTI3NjExOTYy\" data-auth=\"NotApplicable\" data-linkindex=\"25\">SAP Patch Day: August 2026 &#8211; Onapsis<\/a><\/div>\n<\/li>\n<\/ul>\n<\/div>\n<h2><strong style=\"color: #014888; font-family: inherit; font-size: 1.6rem; letter-spacing: 0em;\">Affected resources<\/strong><\/h2>\n<div>The full list of affected systems\/components is as follows:<\/div>\n<div><\/div>\n<ul>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP Commerce Cloud (and Data Hub Adapter):<\/b>\u00a0COM_CLOUD 2211, 2211-JDK21, DHUB_CLOUD 2211<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP Manufacturing Integration and Intelligence:<\/b>\u00a0XMII 15.4, 15.5, MII_ADMIN 15.4, 15.5<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP NetWeaver and ABAP Platform:<\/b>\u00a0KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.22EX2, 7.22EX3, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP ABAP Developer Tools:<\/b>\u00a0SAP_BASIS 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, 920<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP BusinessObjects Business Intelligence Platform (Central Management Server):<\/b>\u00a0ENTERPRISE 430, 2025, 2027<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach):<\/b>\u00a0CTS_UPLOAD_CLT 1<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP Business AI Platform (Approuter):<\/b>\u00a0&lt;23.0.0<\/div>\n<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Through services such as the SAP Security Assessment, Inprosec helps its clients improve the security levels of their SAP systems. August 2026 Notes Monthly Summary and Highlights This month the total number was 31 notes (28 new, 1 security notice and 2 updates), 11 more than in July. This month 4 Hot News were published,&#8230;<\/p>\n","protected":false},"author":6,"featured_media":14597,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[95,61],"tags":[150],"class_list":["post-14595","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sap-notes","category-sap-security-en-2","tag-sap-notes"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.3 (Yoast SEO v28.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>SAP Security Notes, August 2026 - Inprosec<\/title>\n<meta name=\"description\" content=\"All updates to SAP systems notes from august 2026, to stay current and improve the security levels of your SAP systems.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SAP Security Notes, August 2026\" \/>\n<meta property=\"og:description\" content=\"All updates to SAP systems notes from august 2026, to stay current and improve the security levels of your SAP systems.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/\" \/>\n<meta property=\"og:site_name\" content=\"Inprosec\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-18T08:38:32+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T08:38:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/08\/Portada-Notas-SAP-agosto-2026.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Fernando Mosquera\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Fernando Mosquera\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-august-2026\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-august-2026\\\/\"},\"author\":{\"name\":\"Fernando Mosquera\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\"},\"headline\":\"SAP Security Notes, August 2026\",\"datePublished\":\"2026-08-18T08:38:32+00:00\",\"dateModified\":\"2026-08-18T08:38:54+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-august-2026\\\/\"},\"wordCount\":1500,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-august-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Portada-Notas-SAP-agosto-2026.jpg\",\"keywords\":[\"SAP Notes\"],\"articleSection\":[\"SAP Notes\",\"SAP Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-august-2026\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-august-2026\\\/\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-august-2026\\\/\",\"name\":\"SAP Security Notes, August 2026 - Inprosec\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-august-2026\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-august-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Portada-Notas-SAP-agosto-2026.jpg\",\"datePublished\":\"2026-08-18T08:38:32+00:00\",\"dateModified\":\"2026-08-18T08:38:54+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\"},\"description\":\"All updates to SAP systems notes from august 2026, to stay current and improve the security levels of your SAP systems.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-august-2026\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-august-2026\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-august-2026\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Portada-Notas-SAP-agosto-2026.jpg\",\"contentUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Portada-Notas-SAP-agosto-2026.jpg\",\"width\":1200,\"height\":630},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-august-2026\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SAP Security Notes, August 2026\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\",\"name\":\"Inprosec\",\"description\":\"Information security is our priority.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\",\"name\":\"Fernando Mosquera\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"caption\":\"Fernando Mosquera\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"SAP Security Notes, August 2026 - Inprosec","description":"All updates to SAP systems notes from august 2026, to stay current and improve the security levels of your SAP systems.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/","og_locale":"en_US","og_type":"article","og_title":"SAP Security Notes, August 2026","og_description":"All updates to SAP systems notes from august 2026, to stay current and improve the security levels of your SAP systems.","og_url":"https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/","og_site_name":"Inprosec","article_published_time":"2026-08-18T08:38:32+00:00","article_modified_time":"2026-08-18T08:38:54+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/08\/Portada-Notas-SAP-agosto-2026.jpg","type":"image\/jpeg"}],"author":"Fernando Mosquera","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Fernando Mosquera","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/#article","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/"},"author":{"name":"Fernando Mosquera","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2"},"headline":"SAP Security Notes, August 2026","datePublished":"2026-08-18T08:38:32+00:00","dateModified":"2026-08-18T08:38:54+00:00","mainEntityOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/"},"wordCount":1500,"commentCount":0,"image":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/08\/Portada-Notas-SAP-agosto-2026.jpg","keywords":["SAP Notes"],"articleSection":["SAP Notes","SAP Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/","url":"https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/","name":"SAP Security Notes, August 2026 - Inprosec","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/#primaryimage"},"image":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/08\/Portada-Notas-SAP-agosto-2026.jpg","datePublished":"2026-08-18T08:38:32+00:00","dateModified":"2026-08-18T08:38:54+00:00","author":{"@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2"},"description":"All updates to SAP systems notes from august 2026, to stay current and improve the security levels of your SAP systems.","breadcrumb":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/#primaryimage","url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/08\/Portada-Notas-SAP-agosto-2026.jpg","contentUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/08\/Portada-Notas-SAP-agosto-2026.jpg","width":1200,"height":630},{"@type":"BreadcrumbList","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-august-2026\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.inprosec.com\/en\/"},{"@type":"ListItem","position":2,"name":"SAP Security Notes, August 2026"}]},{"@type":"WebSite","@id":"https:\/\/www.inprosec.com\/en\/#website","url":"https:\/\/www.inprosec.com\/en\/","name":"Inprosec","description":"Information security is our priority.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.inprosec.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2","name":"Fernando Mosquera","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","caption":"Fernando Mosquera"}}]}},"_links":{"self":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/14595","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/comments?post=14595"}],"version-history":[{"count":1,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/14595\/revisions"}],"predecessor-version":[{"id":14602,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/14595\/revisions\/14602"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media\/14597"}],"wp:attachment":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media?parent=14595"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/categories?post=14595"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/tags?post=14595"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}