SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful exploitation could allow limited access to another tenant's information, resulting in a low impact on confidentiality. There is no impact on integrity and availability.
References
| Link | Resource |
|---|---|
| https://me.sap.com/notes/3786038 | Permissions Required |
| https://url.sap/sapsecuritypatchday | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-11 01:17
Updated : 2026-09-08 20:20
NVD link : CVE-2026-58239
Mitre link : CVE-2026-58239
CVE.ORG link : CVE-2026-58239
JSON object : View
Products Affected
sap
- approuter
CWE
CWE-807
Reliance on Untrusted Inputs in a Security Decision
