CVE-2026-58230
Received Received - Intake

Sensitive Credential Exposure in SAP Approuter

Vulnerability report for CVE-2026-58230, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: SAP SE

Description

SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality and a low impact on integrity and availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap approuter *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SAP Approuter fails to properly validate token content in certain setups. An attacker could exploit this by sending a specially crafted token to trick the system into sending sensitive credentials to a destination controlled by the attacker. The attack requires specific non-default conditions in the target environment, making it complex to execute.

Impact Analysis

If exploited, this vulnerability could lead to unauthorized access to sensitive credentials, potentially compromising user accounts or system integrity. The impact is limited by the high attack complexity and non-default preconditions required for exploitation.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive credential material, which may result in data breaches. Such breaches could violate GDPR's data protection requirements and HIPAA's safeguards for protected health information, potentially leading to compliance violations and penalties.

Mitigation Strategies

Update SAP Approuter to the latest version to ensure proper token validation. Review and restrict network access to SAP Approuter instances to prevent unauthorized access. Monitor logs for unusual token requests or credential leaks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58230. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart