cbcvebase.
CVE-2026-58237
published 2026-08-11

CVE-2026-58237: WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to…

PriorityP337medium5.9CVSS 3.1
AVNACHPRLUINSUCHILAN
EPSS
0.21%
12.2th percentile
WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could allow the attacker to read sensitive information and perform limited modifications, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.

Affected

1 ranges
VendorProductVersion rangeFixed in
sap_sesap_business_ai_platform
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.