CVE-2026-58237
Multiple vulnerabilities in SAP Business AI Platform (Approuter)
CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th
WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could allow the attacker to read sensitive information and perform limited modifications, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.
| Vendor | sap_se |
| Product | sap business ai platform (approuter) |
| Published | Aug 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for sap_se sap business ai platform (approuter)
Be the first to know when new medium vulnerabilities affecting sap_se sap business ai platform (approuter) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
SAP_SE / SAP Business AI Platform (Approuter)
SAP Approuter node.js package < 23.0.0