What is CVE-2026-58239?
SAP Approuter does not sufficiently validate tenant context in inbound requests. In multitenant environments, an unauthenticated attacker could send crafted requests to gain limited access to another tenant's information under certain conditions.
Azərbaycanca: SAP Approuter daxil olan sorğularda müştəri kontekstini kifayət qədər yoxlamır. Təhlükəsizlik tədbiri olaraq, multitenant mühitlərdə autentifikasiya edilməmiş hücumçu xüsusi hazırlanmış sorğularla məhdud şəkildə başqa müştərinin məlumatlarına çıxış əldə edə bilər.
Related CVEs
link basis: shared vendor: SAP
FAQ1
What risk does CVE-2026-58239 pose in SAP Approuter?
In multitenant environments, an unauthenticated attacker could send crafted requests to gain limited access to another tenant's information under certain conditions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.