high2026-08-11SAP ApprouterCVE-2026-58230

Multiple Vulnerabilities in SAP Approuter — Credential Exfiltration via Token Validation

SAP Approuter (@sap/approuter npm)

Our Take

Eleven vulnerabilities addressed in one note — the Approuter is getting sustained security investment (or sustained attacker attention). This is a new version target (23.0.0) separate from July's 20.10.0 fix, so July's patch does not cover this. BTP shops: upgrade Approuter again.

Vulnerability Detail

SAP Security Note 3786038 addresses eleven distinct vulnerabilities in SAP Approuter. The lead CVE (CVE-2026-58230) involves insufficient token content validation under specific configurations — an unauthenticated attacker can send a specially crafted token that causes the Approuter to forward sensitive credential material to an attacker-controlled destination. Additional vulnerabilities cover IAS, WebSocket, Redis, back-channel logout, and subscription-management flows.

Workaround

Review Approuter configuration for non-default IAS, WebSocket, Redis, and subscription-management settings. Restrict unauthenticated access to Approuter endpoints where possible.

Patch Action

Upgrade @sap/approuter to version 23.0.0 or higher. Apply SAP Note 3786038. Note: this is a different version target than July's Approuter notes (which required 20.10.0) — if you patched in July, you still need this upgrade.

Affected Versions

@sap/approuter < 23.0.0

Patch Info

CVSS Score

7

SAP Note

3786038

CVE

CVE-2026-58230

Published

2026-08-11

← All patches