AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-58238

MEDIUM · CVSS 5.9 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

SAP Approuter is vulnerable to a denial-of-service attack due to insufficient handling of certain requests, which can lead to the component crashing and restarting when triggered by specially crafted input. While the attack requires specific runtime conditions to be met, it poses a significant risk to availability. Organizations using SAP Approuter should prioritize addressing this vulnerability to mitigate potential disruptions in service.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-58238
Severity
MEDIUM
CVSS
5.9
EPSS
0.26%

Original NVD Description

SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specific runtime conditions to be met, making the attack complex to execute. This results in a high impact on availability. There is no impact on confidentiality and integrity.