CVE-2026-58230: Multiple vulnerabilities in SAP Business AI Platform (Approuter)
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality and a low impact on integrity and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58230?
The severity of CVE-2026-58230 is classified as high with a score of 7.
How do I fix CVE-2026-58230?
To fix CVE-2026-58230, apply the latest security patches provided by SAP for the Business AI Platform (Approuter).
What are the risks associated with CVE-2026-58230?
The risks associated with CVE-2026-58230 include potential exposure of sensitive credential material to an attacker.
Who can exploit CVE-2026-58230?
An unauthenticated attacker can exploit CVE-2026-58230 by sending a specially crafted token under specific configurations.
What does CVE-2026-58230 affect?
CVE-2026-58230 affects SAP Business AI Platform, specifically the Approuter component.