Junglewise Threat Intelligence

CVE-2026-58237: SAP Approuter WebSocket authorization bypass

CVE-2026-58237 · Severity: medium · CVSS 5.9 · Published 2026-08-11

Technologies: SAP Approuter. Vendors: SAP.

Executive brief

SAP Approuter is a routing component used to manage access to SAP applications. A flaw in its WebSocket implementation fails to properly verify user permissions, allowing an attacker with low-level access to bypass security controls and read sensitive information. Successful exploitation could expose confidential data and allow limited unauthorized modifications.

Technical details

The vulnerability is an authorization bypass (CWE-285) in the WebSocket functionality of SAP Approuter. The affected component does not perform sufficient authorization checks on certain operations, allowing an attacker with low privileges to access restricted functionality. The attack requires the attacker to have existing (low) privilege access and can be performed remotely over the network via WebSocket. An attacker can read sensitive information and perform limited modifications; there is no impact on availability. A patch is presumed available via SAP Security Patch Day procedures.

Affected products

  • SAP Approuter

Timeline

  • 2026-08-11: disclosed

References