Multiple Vulnerabilities in SAP Approuter — Credential Exfiltration via Token Validation
SAP Approuter (@sap/approuter npm)
Eleven vulnerabilities addressed in one note — the Approuter is getting sustained security investment (or sustained attacker attention). This is a new version target (23.0.0) separate from July's 20.10.0 fix, so July's patch does not cover this. BTP shops: upgrade Approuter again.
Vulnerability Detail
SAP Security Note 3786038 addresses eleven distinct vulnerabilities in SAP Approuter. The lead CVE (CVE-2026-58230) involves insufficient token content validation under specific configurations — an unauthenticated attacker can send a specially crafted token that causes the Approuter to forward sensitive credential material to an attacker-controlled destination. Additional vulnerabilities cover IAS, WebSocket, Redis, back-channel logout, and subscription-management flows.
Workaround
Review Approuter configuration for non-default IAS, WebSocket, Redis, and subscription-management settings. Restrict unauthenticated access to Approuter endpoints where possible.
Patch Action
Upgrade @sap/approuter to version 23.0.0 or higher. Apply SAP Note 3786038. Note: this is a different version target than July's Approuter notes (which required 20.10.0) — if you patched in July, you still need this upgrade.
Affected Versions
Patch Info