Authorization Flaw in SAP Approuter WebSocket Functionality
CVE-2026-58237
5.9MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-58237?
The WebSocket component of SAP Approuter lacks adequate authorization checks, potentially allowing low-privilege attackers to exploit restricted functionalities. Successful exploitation may lead to unauthorized access to sensitive data and limited modifications within the application, thereby affecting confidentiality. However, the integrity and availability of the system remain intact. For more information and mitigation strategies, visit the related resources.
Affected Version(s)
SAP Business AI Platform (Approuter) SAP Approuter node.js package < 23.0.0