High-Impact Unauthorized Access via WebSocket in SAP Approuter
CVE-2026-58237 Published on August 11, 2026

Multiple vulnerabilities in SAP Business AI Platform (Approuter)
WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could allow the attacker to read sensitive information and perform limited modifications, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.

NVD

Vulnerability Analysis

CVE-2026-58237 can be exploited with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
LOW
Availability Impact:
NONE

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE-2026-58237 has been classified to as an AuthZ vulnerability or weakness.


Affected Versions

SAP_SE SAP Business AI Platform (Approuter) Version SAP Approuter node.js package < 23.0.0 is affected by CVE-2026-58237