Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful exploitation could allow limited access to another tenant's information, resulting in a low impact on confidentiality. There is no impact on integrity and availability. | |
| Title | Multiple vulnerabilities in SAP Business AI Platform (Approuter) | |
| Weaknesses | CWE-807 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-08-11T00:15:40.747Z
Reserved: 2026-06-29T19:34:28.222Z
Link: CVE-2026-58239
No data.
Status : Received
Published: 2026-08-11T01:17:21.923
Modified: 2026-08-11T01:17:21.923
Link: CVE-2026-58239
No data.
OpenCVE Enrichment
Updated: 2026-08-11T01:30:04Z