What is CVE-2026-58237?
CVE-2026-58237 involves insufficient authorization checks in the WebSocket functionality of SAP Approuter. A low-privileged attacker could exploit this to access restricted functionality, potentially reading sensitive information and performing limited modifications. Users of SAP Approuter should apply the relevant security patches.
Azərbaycanca: CVE-2026-58237 SAP Approuter-in WebSocket funksiyasında qeyri-kafi avtorizasiya yoxlamaları ilə bağlıdır. Aşağı səlahiyyətli hücumçu bu zəiflikdən istifadə edərək məhdudlaşdırılmış funksionallığa daxil ola, həssas məlumatları oxuya və məhdud dəyişikliklər edə bilər. SAP Approuter istifadəçiləri müvafiq təhlükəsizlik yamalarını tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: SAP
FAQ2
Which functionality of which SAP product is affected by CVE-2026-58237?
CVE-2026-58237 involves insufficient authorization checks in the WebSocket functionality of SAP Approuter.
What can a low-privileged attacker do by exploiting this vulnerability?
A low-privileged attacker could access restricted functionality, potentially reading sensitive information and performing limited modifications.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.