CVE-2026-58239

SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful exploitation could allow limited access to another tenant's information, resulting in a low impact on confidentiality. There is no impact on integrity and availability.
References
Link Resource
https://me.sap.com/notes/3786038 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:approuter:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-08-11 01:17

Updated : 2026-09-08 20:20


NVD link : CVE-2026-58239

Mitre link : CVE-2026-58239

CVE.ORG link : CVE-2026-58239


JSON object : View

Products Affected

sap

  • approuter
CWE
CWE-807

Reliance on Untrusted Inputs in a Security Decision