CVE-2026-44745High· 8.1▾ TwilightSAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.
approuter < 21.2.0Upgrade past the affected range:
approuter 21.2.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-58230High· 7.0SAP Approuter does not sufficiently validate certain token content under specific configurations
CVE-2026-66777Medium· 5.9SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations
CVE-2026-66778Medium· 5.3SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components
CVE-2026-58237Medium· 5.9WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality
CVE-2026-58238Medium· 5.9SAP Approuter does not sufficiently handle certain requests under specific conditions
CVE-2026-58239Low· 3.7SAP Approuter does not sufficiently validate tenant context in inbound requests