High severity7.0NVD Advisory· Published Aug 11, 2026· Updated Sep 8, 2026
CVE-2026-58230
CVE-2026-58230
Description
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality and a low impact on integrity and availability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@sap/approuternpm | < 23.0.0 | 23.0.0 |
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-vhh6-v828-x62fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-58230ghsaADVISORY
- url.sap/sapsecuritypatchdaynvdVendor AdvisoryWEB
- me.sap.com/notes/3786038nvdPermissions RequiredWEB
News mentions
1- Critical SAP Vulnerabilities Let Attackers Inject Malicious Code and Corrupt MemoryCyber Security News · Aug 11, 2026