๐Ÿ” CVE Alert

CVE-2026-58237

MEDIUM 5.9

Multiple vulnerabilities in SAP Business AI Platform (Approuter)

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could allow the attacker to read sensitive information and perform limited modifications, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.

Vendor sap_se
Product sap business ai platform (approuter)
Published Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for sap_se sap business ai platform (approuter)

Be the first to know when new medium vulnerabilities affecting sap_se sap business ai platform (approuter) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

SAP_SE / SAP Business AI Platform (Approuter)
SAP Approuter node.js package < 23.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
me.sap.com: https://me.sap.com/notes/3786038 url.sap: https://url.sap/sapsecuritypatchday