Record summary

CVE-2026-58238 has a selected CVSS score of 5.9 (medium).

Description

SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specific runtime conditions to be met, making the attack complex to execute. This results in a high impact on availability. There is no impact on confidentiality and integrity.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

SAP Business AI Platform (Approuter)

Browse SAP_SE / SAP Business AI Platform (Approuter)

Default status: unaffected

CVE ListSAP Approuter node.js package < 23.0.0affected

References

3