PT-2026-70026 · Sap · Sap Approuter

CVE-2026-58230

·

Published

2026-08-11

·

Updated

2026-08-27

CVSS v3.1

7.0

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions SAP Approuter (affected versions not specified)
Description SAP Approuter fails to sufficiently validate certain token content under specific configurations. An unauthenticated attacker can send a specially crafted token to force the transmission of sensitive credential material to a destination controlled by the attacker. This issue requires non-default preconditions in the target environment, resulting in high attack complexity, high impact on confidentiality, and low impact on integrity and availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58230
GHSA-VHH6-V828-X62F

Affected Products

Sap Approuter