Sceawere
Vulnerability Detail
CVE-2026-58230UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SAP Approuter Token Validation Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7
- Creation Date
- 4h ago
- Vendor
- SAP_SE
- Product
- SAP Business AI Platform (Approuter)
- Attack Type
- CWE-601: URL Redirection to Untrusted Site
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality and a low impact on integrity and availability.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.0",
"pubDate": "2026-08-11T01:17:21.307Z",
"pubdate": "2026-08-11T01:17:21.307Z",
"executiveSummary": "An insufficient token validation vulnerability has been identified in SAP Approuter. The flaw allows an unauthenticated remote attacker to transmit a specially crafted token, inducing the application to exfiltrate sensitive credential material to an attacker-controlled destination under specific non-default configurations.\nThe vulnerability carries a high impact on confidentiality and a low impact on integrity and availability. Although the exploitation yields severe credential exposure, the overall risk is constrained by high attack complexity, which necessitates specific non-default preconditions within the target operational environment.\nAffected systems involve deployments of SAP Approuter utilizing configurations where token content is not adequately verified. Attack capabilities are limited to unauthenticated network vectors, provided the prerequisite environmental configurations are met.",
"technicalDetails": "The root cause of the vulnerability resides in the insufficient validation mechanics applied to specific token contents processed by the SAP Approuter component under non-default configurations.\nThe vulnerable component is the token validation subsystem of SAP Approuter, which fails to properly sanitize or verify incoming token structures before initiating downstream communications or handling credential payloads.\nThe exploitation method requires an unauthenticated attacker to construct and transmit a specially crafted token to the vulnerable SAP Approuter instance over the network.\nThe step-by-step attack flow proceeds as follows: First, the attacker identifies a target SAP Approuter deployment running with the requisite non-default configuration preconditions. Second, the attacker crafts a malicious token designed to exploit the parsing or routing logic of the token validation routine. Third, the attacker transmits this crafted payload to the exposed service endpoint. Fourth, upon receiving the input, the application fails to properly validate the token content, leading to the processing and transmission of sensitive credential material to an attacker-controlled destination.\nAuthentication and privilege requirements for the initial initiation of the attack are unauthenticated, meaning no prior credentials or administrative privileges are required to send the malicious token.\nThe network exposure involves remote accessibility to the SAP Approuter instance where the vulnerable token processing logic is exposed.\nThe payload behavior forces the application to misroute or leak internal cryptographic or authentication credentials outward to an external endpoint controlled by the adversary.\nThe post-exploitation impact centers on a severe breach of confidentiality, as the exfiltrated sensitive credential material can potentially be leveraged by the attacker for further unauthorized access within the ecosystem."
}