What is CVE-2026-58244?
A vulnerability in SAP Manufacturing Integration and Intelligence (MII) where missing authorization checks on a specific application function allow a low-privileged authenticated attacker to access information intended for privileged users. Successful exploitation could lead to unauthorized disclosure of restricted data. Applying the security patch released by SAP is recommended.
Azərbaycanca: SAP MII sistemində aşağı imtiyazlı autentifikasiya olunmuş hücumçuya müəyyən tətbiq funksiyası üzərində lazımi səlahiyyət yoxlamasının aparılmaması səbəbindən məxfi məlumatlara icazəsiz giriş imkanı yaradan zəiflikdir. Bu boşluqdan istifadə edərək hücumçu yalnız yüksək imtiyazlı istifadəçilər üçün nəzərdə tutulmuş məlumatları oxuya bilər. SAP tərəfindən buraxılmış təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: SAP
FAQ1
What type of unauthorized access does CVE-2026-58244 allow in SAP MII?
This vulnerability allows a low-privileged authenticated attacker to gain unauthorized access to restricted data intended for privileged users due to missing authorization checks on a specific application function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.