Junglewise Threat Intelligence

CVE-2026-58238: SAP Approuter denial of service due to insufficient request handling

CVE-2026-58238 · Severity: medium · CVSS 5.9 · Published 2026-08-11

Technologies: SAP Approuter. Vendors: SAP.

Executive brief

SAP Approuter is a routing and authentication component used in SAP Cloud Platform applications. An unauthenticated attacker can send specially crafted requests that cause the service to crash and restart, disrupting availability to legitimate users. The attack requires specific runtime conditions to be present, making it moderately difficult to execute in practice.

Technical details

This vulnerability is a denial of service (DoS) flaw in SAP Approuter's request handling logic. An unauthenticated attacker can send specially crafted input that triggers a crash and restart of the component, though exploitation requires specific runtime conditions to be met, increasing the complexity of the attack. The attack is network-accessible and requires no prior authentication or user interaction. Successful exploitation results in service unavailability without impact to data confidentiality or integrity. Patches are available through SAP Security Patch Day releases.

Affected products

  • SAP Approuter

Timeline

  • 2026-08-11: disclosed

References