CVE-2026-58239: Multiple vulnerabilities in SAP Business AI Platform (Approuter)
SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful exploitation could allow limited access to another tenant's information, resulting in a low impact on confidentiality. There is no impact on integrity and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58239?
The severity of CVE-2026-58239 is rated as low with a score of 3.7.
How do I fix CVE-2026-58239?
To address CVE-2026-58239, ensure that your SAP Business AI Platform (Approuter) is updated to the latest version as per the provided security patches.
What impact does CVE-2026-58239 have on SAP Business AI Platform?
CVE-2026-58239 allows attackers to potentially spoof tenant context, leading to limited unauthorized access to another tenant's information.
Who is affected by CVE-2026-58239?
CVE-2026-58239 affects users of SAP Business AI Platform (Approuter) who may be vulnerable due to inadequate tenant context validation.
Is authentication required to exploit CVE-2026-58239?
CVE-2026-58239 can be exploited by unauthenticated attackers, making it more concerning for affected users.