Description
SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specific runtime conditions to be met, making the attack complex to execute. This results in a high impact on availability. There is no impact on confidentiality and integrity.
Published: 2026-08-11
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The SAP Approuter component fails to handle certain requests when specific runtime conditions are present. An attacker who does not need authentication can send crafted input that triggers a crash and forced restart. Successful exploitation strictly depends on meeting those runtime conditions, making the attack more complex than a simple request. The result is a denial of service that impacts availability; there is no effect on confidentiality or integrity.

Affected Systems

SAP Business AI Platform (Approuter) from SAP SE. No specific version information is provided.

Risk and Exploitability

The CVSS score of 5.9 places this vulnerability in the moderate range. The EPSS score is not available, so overall likelihood cannot be quantified, but the attack requires precise runtime conditions and the component lacks authentication, making the exploitation path nontrivial. The vulnerability is not listed in the CISA KEV catalog, so no known active exploits are documented. The primary risk is that a successful exploit would cause a service interruption through repeated crashes and restarts, potentially leading to extended downtime if attackers time the attacks to coincide with critical processing windows.

Generated by OpenCVE AI on August 11, 2026 at 01:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP-published patch from note 3786038 to the Approuter component immediately.
  • Restrict unauthenticated access to the Approuter endpoint by configuring authentication or firewall rules before the patch is applied.
  • Verify that the Approuter runtime environment is configured with proper input validation and error handling to prevent crashes on malformed input.
  • Continuously monitor system logs for unexpected restarts or crashes and set alerts for abnormal restart frequency.

Generated by OpenCVE AI on August 11, 2026 at 01:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specific runtime conditions to be met, making the attack complex to execute. This results in a high impact on availability. There is no impact on confidentiality and integrity.
Title Multiple vulnerabilities in SAP Business AI Platform (Approuter)
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T00:15:29.329Z

Reserved: 2026-06-29T19:34:28.222Z

Link: CVE-2026-58238

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T01:30:04Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling