CVE-2026-58237
Received Received - Intake

WebSocket Authorization Bypass in SAP Approuter

Vulnerability report for CVE-2026-58237, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: SAP SE

Description

WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could allow the attacker to read sensitive information and perform limited modifications, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap approuter *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in SAP Approuter's WebSocket functionality allows attackers with low privileges to bypass authorization checks and access restricted features. It could lead to unauthorized reading of sensitive data and limited modifications, primarily affecting confidentiality with minor integrity impact.

Detection Guidance

To detect this vulnerability, inspect SAP Approuter WebSocket traffic for unauthorized access attempts to restricted functionality. Check logs for low-privilege users accessing sensitive endpoints. Monitor for unusual read or modification operations on sensitive data.

Impact Analysis

An attacker could exploit this to read sensitive information and make limited changes, potentially exposing confidential data or altering system behavior in unintended ways. The impact is higher on confidentiality than integrity.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles or HIPAA's confidentiality requirements. Organizations may face compliance violations and potential penalties due to data exposure.

Mitigation Strategies

Apply the latest security patches provided by SAP for the Approuter component. Review and restrict user privileges to minimize access to sensitive functionality. Monitor network traffic for unusual WebSocket connections or unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58237. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart