What is CVE-2026-58243?
SAP ABAP Development Tools lacks proper authorization checks for certain functionality, enabling a low-privileged attacker to perform unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could lead to the reading of sensitive data. Affected systems should be updated with the relevant security patches.
Azərbaycanca: SAP ABAP Development Tools-da müəyyən funksionallıq üçün lazımi avtorizasiya yoxlamaları aparılmır ki, bu da aşağı səlahiyyətli hücumçuya SAP NetWeaver AS ABAP-a qarşı icazəsiz verilənlər bazası əməliyyatları icra etməyə imkan verir. Uğurlu istismar həssas məlumatların oxunmasına səbəb ola bilər. Təsirə məruz qalan sistemlərin təhlükəsizlik yamaları ilə yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: SAP
FAQ2
What does CVE-2026-58243 allow in SAP systems?
This vulnerability enables a low-privileged attacker to perform unauthorized database operations against SAP NetWeaver AS ABAP, which can lead to the reading of sensitive data.
What measures are recommended to protect against CVE-2026-58243?
It is recommended to update the affected systems with the relevant security patches.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.