HIGH

CVE-2026-58230

Sap Approuter 2026-08-11 CVSS v3.1
CVSS
7

Description

SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality and a low impact on integrity and availability.

Weakness (CWE)

CWE-601 Open Redirect

EPSS Score

0.24%
Probability of exploitation in next 30 days
15.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE