Authentication Bypass Vulnerability in SAP Approuter
CVE-2026-58230
7HIGH
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-58230?
SAP Approuter fails to adequately validate specific token content, which can be exploited under particular configurations. An unauthenticated attacker might exploit this flaw by sending a specially crafted token. This could lead to the unauthorized transmission of sensitive credentials to a malicious destination, thereby jeopardizing the confidentiality of the affected systems. The complexity of the attack is heightened due to specific non-default preconditions needed in the environment, making proactive security measures essential.
Affected Version(s)
SAP Business AI Platform (Approuter) SAP Approuter node.js package < 23.0.0