Advisory
A note with CVSS 7.0 for component BC-XS-APR was released by SAP on 11.08.2026. The correction/advisory 3786038 was described with "3786038 - [CVE-2026-58230] Multiple vulnerabilities in SAP Business AI Platform (Approuter)" and affects the system type SAP Approuter.
A workaround exists, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process.
The vulnerability addressed is information disclosurecross-site request forgery (xsrf) denial of service (dos)missing authorization checkimproper authentication checkhttp request smuggling within SAP Approuter.
Risk specification
The SAP Approuter package is affected by multiple security vulnerabilities. SAP Approuter allows an unauthenticated attacker to send a specially crafted token that bypasses token validation under specific configurations, resulting in sensitive credential material being exfiltrated to an attacker-controlled destination. SAP Approuter allows an authenticated attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, to bypass identity checks in certain callback flows, resulting in impersonation of a trusted internal component. SAP Approuter allows an authenticated attacker with low privileges to send specially crafted requests that bypass authorization checks before reaching backend destinations, resulting in unauthorized access to protected resources and limited modifications beyond the user's assigned scope. SAP Approuter allows an authenticated attacker with low privileges to send a specially crafted request that bypasses session integrity verification and loads another user's session context, resulting in unauthorized access to that user's session and limited modifications under their identity. SAP Approuter allows an authenticated attacker with low privileges to exploit insufficient authorization checks in WebSocket functionality, resulting in access to restricted features, disclosure of sensitive information, and limited modifications. SAP Approuter allows an unauthenticated attacker to send specially crafted input that exploits insufficient request handling under specific runtime conditions, resulting in the component crashing and restarting. SAP Approuter allows an unauthenticated attacker to send specially crafted request headers that bypass sanitization before being forwarded to internal components, resulting in limited unauthorized access to information. SAP Approuter allows an authenticated attacker with low privileges to send high volumes of data without consuming responses, exploiting insufficient flow control and resulting in unbounded memory growth and service degradation. SAP Approuter allows an unauthenticated attacker to craft a malicious link and trick a victim into following it, exploiting the absence of CSRF protection on the authentication flow by default and resulting in the victim's session being bound to an attacker-controlled identity. SAP Approuter allows an authenticated attacker with low privileges to exploit inconsistent error condition handling under a non-default configuration, resulting in service disruption. SAP Approuter allows an unauthenticated attacker to send specially crafted requests that spoof the tenant context under conditions not fully within their control, resulting in limited unauthorized access to another tenant's data.
Solution
SAP Approuter has been updated to version 23.0.0, which addresses the vulnerabilities. Although an alternative solution exists, it is advisable to apply the correction! This is the workaround, which was suggested by the SAP security experts: "Information Disclosure [CVE-2026-58230]: Bind IAS to the Approuter with x509 credentials. Cross-Site Request Forgery [CVE-2026-66775]: Set STATE_PARAMETER_SECRET to true explicitly.".
