CVE-2026-58248

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected component resolves these references and exposes the contents of sensitive server-side files within the resulting report. This results in a high impact on confidentiality, with no impact on integrity and availability.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-11 01:17

Updated : 2026-08-26 19:00


NVD link : CVE-2026-58248

Mitre link : CVE-2026-58248

CVE.ORG link : CVE-2026-58248


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference