What is CVE-2026-58230?
SAP Approuter fails to sufficiently validate specific token content under certain configurations, allowing an unauthenticated attacker to send a crafted token and redirect sensitive credential material to a controlled destination. The attack has high complexity due to non-default conditions, so applying SAP's recommended patches is crucial.
Azərbaycanca: SAP Approuter xüsusi konfiqurasiyalar altında müəyyən token məzmununu kifayət qədər yoxlamadığı üçün autentifikasiya olunmamış hücumçu xüsusi hazırlanmış token göndərərək həssas məlumatları ələ keçirə bilər. Bu zəiflik yalnız qeyri-standart konfiqurasiyalarda yüksək mürəkkəblikdə istismar oluna bildiyi üçün əsas tövsiyə SAP tərəfindən verilən yeniləmələri tətbiq etməkdir.
Related CVEs
link basis: shared vendor: SAP
FAQ2
What is CVE-2026-58230 and under what conditions can it be exploited?
CVE-2026-58230 occurs because SAP Approuter fails to sufficiently validate specific token content. This vulnerability can only be exploited under non-default configurations with high complexity.
What is the main recommendation to protect against CVE-2026-58230?
The main recommendation is to apply the patches provided by SAP.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.