Authorization Flaw in SAP Approuter WebSocket Functionality
CVE-2026-58237

5.9MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 August 2026

What is CVE-2026-58237?

The WebSocket component of SAP Approuter lacks adequate authorization checks, potentially allowing low-privilege attackers to exploit restricted functionalities. Successful exploitation may lead to unauthorized access to sensitive data and limited modifications within the application, thereby affecting confidentiality. However, the integrity and availability of the system remain intact. For more information and mitigation strategies, visit the related resources.

Affected Version(s)

SAP Business AI Platform (Approuter) SAP Approuter node.js package < 23.0.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.