← Vulnerability feed

Vulnerability record · CVE-2026-58237 · published 11 August 2026

CVE-2026-58237: Sap approuter missing authorization vulnerability

Sap · Approuter

WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could allow the attacker to read sensitive information and perform limited modifications, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.

5.9 CVSS 3.1 Medium EPSS 0.28% · top 81.9% CWE-862 · Missing authorization
5.9CVSS 3.1 base score
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
8 Sep 2026Last modified by NVD

Description

WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could allow the attacker to read sensitive information and perform limited modifications, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://me.sap.com/notes/3786038 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory

Track CVE-2026-58237 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2026-27690Sap approuter http request smuggling vulnerabilityDue to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads t…EPSS 0.68%8.1CVE-2026-44745Sap approuter open redirect vulnerabilitySAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthent…EPSS 0.47%7.0CVE-2026-58230Sap approuter open redirect vulnerabilitySAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially …EPSS 0.31%6.4CVE-2026-66760Sap approuter improper certificate validation vulnerabilitySAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from …EPSS 0.18%5.9CVE-2026-66776Sap approuter improper verification of cryptographic signature vulnerabilitySAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker …EPSS 0.20%5.9CVE-2026-66777Sap approuter path traversal vulnerabilitySAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the r…EPSS 0.44%5.9CVE-2026-58238Sap approuter allocation without limits vulnerabilitySAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input…EPSS 0.43%5.3CVE-2026-66778Sap approuter vulnerabilitySAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker co…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2026-58237), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.