AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-58230

HIGH · CVSS 7 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

SAP Approuter is vulnerable due to inadequate validation of token content, allowing unauthenticated attackers to exploit this weakness by sending crafted tokens that can exfiltrate sensitive credential information to an external destination. Although the attack complexity is high, organizations using SAP Approuter should prioritize this vulnerability due to its significant impact on confidentiality. It is essential for security teams to assess their configurations and implement necessary mitigations to protect against potential data breaches.

CVE
CVE-2026-58230
Severity
HIGH
CVSS
7
EPSS
0.24%

Original NVD Description

SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality and a low impact on integrity and availability.