CVE-2026-58238: Multiple vulnerabilities in SAP Business AI Platform (Approuter)
SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specific runtime conditions to be met, making the attack complex to execute. This results in a high impact on availability. There is no impact on confidentiality and integrity.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58238?
The severity of CVE-2026-58238 is classified as medium with a CVSS score of 5.9.
How do I fix CVE-2026-58238?
To fix CVE-2026-58238, update your SAP Business AI Platform (Approuter) to the latest version as provided by SAP.
What type of attack does CVE-2026-58238 allow?
CVE-2026-58238 allows unauthenticated attackers to crash and restart the SAP Approuter through specially crafted input.
What are the prerequisites for exploiting CVE-2026-58238?
Successful exploitation of CVE-2026-58238 requires specific runtime conditions to be met, making the attack complex.
What component is affected by CVE-2026-58238?
CVE-2026-58238 affects the SAP Business AI Platform, specifically the Approuter component.