CVE-2026-58230High· 7.0▾ TwilightSAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlle…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality and a low impact on integrity and availability.
approuter < 23.0.0Upgrade past the affected range:
approuter 23.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-66777Medium· 5.9SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations
CVE-2026-66778Medium· 5.3SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components
CVE-2026-58237Medium· 5.9WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality
CVE-2026-58238Medium· 5.9SAP Approuter does not sufficiently handle certain requests under specific conditions
CVE-2026-58239Low· 3.7SAP Approuter does not sufficiently validate tenant context in inbound requests
CVE-2026-66760Medium· 6.4SAP Approuter does not correctly validate client certificates in certain callback flows