High Severity
Affected system
SAP Approuter
CVSS
7.0
Component
BC-XS-APR
Patch Day
2026-08
Released on
2026/08/11
SAP Note
3786038
Workaround
Yes
  • Share with:

Advisory

A note with CVSS 7.0 for component BC-XS-APR was released by SAP on 11.08.2026. The correction/advisory 3786038 was described with "3786038 - [CVE-2026-58230] Multiple vulnerabilities in SAP Business AI Platform (Approuter)" and affects the system type SAP Approuter.

A workaround exists, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process.

The vulnerability addressed is information disclosurecross-site request forgery (xsrf) denial of service (dos)missing authorization checkimproper authentication checkhttp request smuggling within SAP Approuter.

Risk specification

The SAP Approuter package is affected by multiple security vulnerabilities. SAP Approuter allows an unauthenticated attacker to send a specially crafted token that bypasses token validation under specific configurations, resulting in sensitive credential material being exfiltrated to an attacker-controlled destination. SAP Approuter allows an authenticated attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, to bypass identity checks in certain callback flows, resulting in impersonation of a trusted internal component. SAP Approuter allows an authenticated attacker with low privileges to send specially crafted requests that bypass authorization checks before reaching backend destinations, resulting in unauthorized access to protected resources and limited modifications beyond the user's assigned scope. SAP Approuter allows an authenticated attacker with low privileges to send a specially crafted request that bypasses session integrity verification and loads another user's session context, resulting in unauthorized access to that user's session and limited modifications under their identity. SAP Approuter allows an authenticated attacker with low privileges to exploit insufficient authorization checks in WebSocket functionality, resulting in access to restricted features, disclosure of sensitive information, and limited modifications. SAP Approuter allows an unauthenticated attacker to send specially crafted input that exploits insufficient request handling under specific runtime conditions, resulting in the component crashing and restarting. SAP Approuter allows an unauthenticated attacker to send specially crafted request headers that bypass sanitization before being forwarded to internal components, resulting in limited unauthorized access to information. SAP Approuter allows an authenticated attacker with low privileges to send high volumes of data without consuming responses, exploiting insufficient flow control and resulting in unbounded memory growth and service degradation. SAP Approuter allows an unauthenticated attacker to craft a malicious link and trick a victim into following it, exploiting the absence of CSRF protection on the authentication flow by default and resulting in the victim's session being bound to an attacker-controlled identity. SAP Approuter allows an authenticated attacker with low privileges to exploit inconsistent error condition handling under a non-default configuration, resulting in service disruption. SAP Approuter allows an unauthenticated attacker to send specially crafted requests that spoof the tenant context under conditions not fully within their control, resulting in limited unauthorized access to another tenant's data.

Solution

SAP Approuter has been updated to version 23.0.0, which addresses the vulnerabilities.  Although an alternative solution exists, it is advisable to apply the correction! This is the workaround, which was suggested by the SAP security experts: "Information Disclosure [CVE-2026-58230]: Bind IAS to the Approuter with x509 credentials. Cross-Site Request Forgery [CVE-2026-66775]: Set STATE_PARAMETER_SECRET to true explicitly.".

The advisory is valid for

 

 

Disclaimer

SecurityBridge takes the security of SAP products very seriously. We very much encourage the responsible disclosure of security vulnerabilities. If you have detected a vulnerability concerning one of the SAP software products – either in the latest or in a former product version follow the guidelines and processes in accordance with the SAP portal page “Report a Security Vulnerability to SAP”.

The advisories found within the SecurityBridge advisory are generated and continuously enriched by our Team at SecurityBridge and affiliated security consultants, partners, customers of the SecurityBridge Platform, SAP support, and advisory groups.

We do not disclose zero-day vulnerabilities unless a security patch has been made available to the public. In such case, the platform only provides details on which version or signature updates are available within the SecurityBridge platform in order to monitor or measure the vulnerability.

In accordance with SAP guidelines, SecurityBridge only discloses issues where the fixing security note has been released. The vulnerability platform makes no references to available exploits or Proof of Concepts (PoC). Advisories and vulnerabilities will always mention the fixing security note or hints to the corresponding SAP documentation.

SecurityBridge

SecurityBridge for SAP©
empowers security teams with forward-looking, high fidelity, adversary-focused intelligence and actionable events from SAP Netweaver based systems.

Follow us