CVE-2026-58237
published 2026-08-11CVE-2026-58237: WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to…
PriorityP337medium5.9CVSS 3.1
AVNACHPRLUINSUCHILAN
EPSS
0.21%
12.2th percentile
WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could allow the attacker to read sensitive information and perform limited modifications, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap_se | sap_business_ai_platform | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SAP Approuter improper authorization
vuldb·2026-08-11·CVSS 5.9
CVE-2026-58237 [MEDIUM] SAP Approuter improper authorization
A vulnerability was found in SAP Approuter. It has been classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper authorization.
This vulnerability is traded as CVE-2026-58237. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality.
ghsa_unreviewed·2026-08-11
CVE-2026-58237 [MEDIUM] CWE-862 WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality.
WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could allow the attacker to read sensitive information and perform limited modifications, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-11
Published