Description
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality and a low impact on integrity and availability.
Published: 2026-08-11
Score: 7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP Approuter fails to fully validate token contents under certain configurations, allowing an unauthenticated attacker to send a crafted token that can cause the system to send sensitive credential material to an attacker-controlled destination. This flaw results in a high confidentiality impact while having only a minor influence on integrity and availability.

Affected Systems

SAP Business AI Platform (Approuter) is affected. The flaw is present in all deployment versions of this product that have the default token validation configuration enabled. No specific product versions are listed, so any instance where the vulnerable token processing path is active is at risk.

Risk and Exploitability

The CVSS score of 7 indicates a high severity vulnerability. Exploitation requires non-default preconditions, implying a high attack complexity and that the attacker must first identify an environment with the specific configuration that allows the vulnerability. The EPSS score is not available, and the vulnerability is not listed in KEV, suggesting no widespread public exploitation yet. Nevertheless, the potential for an unauthenticated attacker to exfiltrate credential data makes timely remediation essential.

Generated by OpenCVE AI on August 11, 2026 at 01:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch referenced in SAP Note 3786038 to correct the token validation flaw.
  • If the patch cannot be applied immediately, modify Approuter configuration to block or disable the vulnerable redirect or token validation logic that forwards external tokens.
  • Perform an internal review of token handling to ensure no other components expose similar weaknesses and apply network segmentation to limit exposure of the Approuter to untrusted traffic.

Generated by OpenCVE AI on August 11, 2026 at 01:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality and a low impact on integrity and availability.
Title Multiple vulnerabilities in SAP Business AI Platform (Approuter)
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T00:12:16.119Z

Reserved: 2026-06-29T19:34:28.221Z

Link: CVE-2026-58230

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T01:30:04Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')