Description
SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful exploitation could allow limited access to another tenant's information, resulting in a low impact on confidentiality. There is no impact on integrity and availability.
Published: 2026-08-11
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP Approuter fails to properly validate tenant context in inbound requests. An unauthenticated attacker can send crafted requests that spoof another tenant’s context, potentially gaining limited access to that tenant’s data. This condition results in a low confidentiality impact. The vulnerability does not affect integrity or availability.

Affected Systems

The vulnerability affects SAP Business AI Platform (Approuter). No specific product versions are listed in the available data, so any deployment of this platform could be at risk.

Risk and Exploitability

The CVSS score of 3.7 indicates low severity. EPSS data is not published, and the vulnerability is not listed in CISA KEV, implying no known exploits. The likely attack vector involves direct network traffic to the Approuter, requiring no prior authentication. Since the exploitation grants only limited access to another tenant’s information, the overall risk is modest, but it remains relevant for environments with multi‑tenant configurations.

Generated by OpenCVE AI on August 11, 2026 at 01:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP security patch referenced in SAP Note 3786038.
  • Verify that the Approuter enforces proper tenant context validation before processing requests.
  • Monitor logs for suspicious tenant context spoofing attempts and block offending IPs as needed.

Generated by OpenCVE AI on August 11, 2026 at 01:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap Business Ai Platform (approuter)
Vendors & Products Sap Se
Sap Se sap Business Ai Platform (approuter)

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful exploitation could allow limited access to another tenant's information, resulting in a low impact on confidentiality. There is no impact on integrity and availability.
Title Multiple vulnerabilities in SAP Business AI Platform (Approuter)
Weaknesses CWE-807
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Sap Se Sap Business Ai Platform (approuter)
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T14:31:07.219Z

Reserved: 2026-06-29T19:34:28.222Z

Link: CVE-2026-58239

cve-icon Vulnrichment

Updated: 2026-08-11T14:31:01.783Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T01:17:21.923

Modified: 2026-08-26T19:00:14.450

Link: CVE-2026-58239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:20:58Z

Weaknesses
  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision