---
id: CVE-2026-58238
title: >-
  SAP Approuter does not sufficiently handle certain requests under specific
  conditions
summary: >-
  SAP Approuter does not sufficiently handle certain requests under specific
  conditions. An unauthenticated attacker could send specially crafted input
  that causes the component to crash and restart. Successful exploitation
  requires specif…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
vendor: sap
product: approuter
affected:
  - approuter < 23.0.0
patched:
  - approuter 23.0.0
published: '2026-08-11'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:22:11.230'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-58238'
references:
  - url: 'https://me.sap.com/notes/3786038'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
epss: 0.00429
epssPercentile: 0.34477
ingestedAt: '2026-09-08T21:11:12.274Z'
---

## Overview

SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specific runtime conditions to be met, making the attack complex to execute. This results in a high impact on availability. There is no impact on confidentiality and integrity.

## Affected

- `approuter < 23.0.0`

## Remediation

Upgrade past the affected range:

- `approuter 23.0.0`
