CVE-2026-58238
Multiple vulnerabilities in SAP Business AI Platform (Approuter)
CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th
SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specific runtime conditions to be met, making the attack complex to execute. This results in a high impact on availability. There is no impact on confidentiality and integrity.
| Vendor | sap_se |
| Product | sap business ai platform (approuter) |
| Published | Aug 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for sap_se sap business ai platform (approuter)
Be the first to know when new medium vulnerabilities affecting sap_se sap business ai platform (approuter) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
SAP_SE / SAP Business AI Platform (Approuter)
SAP Approuter node.js package < 23.0.0