CVE-2026-58238
Received Received - Intake

SAP Approuter Denial of Service via Request Handling

Vulnerability report for CVE-2026-58238, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: SAP SE

Description

SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specific runtime conditions to be met, making the attack complex to execute. This results in a high impact on availability. There is no impact on confidentiality and integrity.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap approuter *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SAP Approuter fails to properly handle certain requests under specific conditions. An unauthenticated attacker could exploit this by sending specially crafted input, causing the component to crash and restart. The attack requires specific runtime conditions, making it complex to execute. It primarily impacts availability with no effect on confidentiality or integrity.

Detection Guidance

Detection of CVE-2026-58238 requires monitoring for crashes or restarts of the SAP Approuter component under specific runtime conditions. Check application logs for unexpected terminations or restart events. Ensure SAP Approuter is running the latest patched version to mitigate the issue.

Impact Analysis

This vulnerability could lead to service disruptions as the Approuter crashes and restarts repeatedly. While it does not expose sensitive data or alter information, the downtime may affect business operations relying on SAP Approuter for request handling.

Compliance Impact

This vulnerability primarily impacts availability by causing the SAP Approuter to crash and restart under specific conditions. It does not affect confidentiality or integrity, which are critical for GDPR and HIPAA compliance. However, repeated disruptions could lead to service unavailability, potentially violating availability requirements in these standards.

Mitigation Strategies

Apply the latest security patches provided by SAP for Approuter. Monitor application logs for unusual crashes or restarts. Ensure runtime conditions that could trigger the vulnerability are minimized or eliminated.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58238. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart