CVE-2026-58238 PUBLISHED

Multiple vulnerabilities in SAP Business AI Platform (Approuter)

Assigner: sap
Reserved: 29.06.2026 Published: 11.08.2026 Updated: 11.08.2026

SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specific runtime conditions to be met, making the attack complex to execute. This results in a high impact on availability. There is no impact on confidentiality and integrity.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 5.9

Product Status

Vendor SAP_SE
Product SAP Business AI Platform (Approuter)
Versions Default: unaffected
  • Version SAP Approuter node.js package < 23.0.0 is affected

References

Problem Types