Description
SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful exploitation could allow limited access to another tenant's information, resulting in a low impact on confidentiality. There is no impact on integrity and availability.
Published: 2026-08-11
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP Approuter fails to properly validate tenant context in inbound requests. An unauthenticated attacker can send crafted requests that spoof another tenant’s context, potentially gaining limited access to that tenant’s data. This condition results in a low confidentiality impact. The vulnerability does not affect integrity or availability.

Affected Systems

The vulnerability affects SAP Business AI Platform (Approuter). No specific product versions are listed in the available data, so any deployment of this platform could be at risk.

Risk and Exploitability

The CVSS score of 3.7 indicates low severity. EPSS data is not published, and the vulnerability is not listed in CISA KEV, implying no known exploits. The likely attack vector involves direct network traffic to the Approuter, requiring no prior authentication. Since the exploitation grants only limited access to another tenant’s information, the overall risk is modest, but it remains relevant for environments with multi‑tenant configurations.

Generated by OpenCVE AI on August 11, 2026 at 01:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP security patch referenced in SAP Note 3786038.
  • Verify that the Approuter enforces proper tenant context validation before processing requests.
  • Monitor logs for suspicious tenant context spoofing attempts and block offending IPs as needed.

Generated by OpenCVE AI on August 11, 2026 at 01:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful exploitation could allow limited access to another tenant's information, resulting in a low impact on confidentiality. There is no impact on integrity and availability.
Title Multiple vulnerabilities in SAP Business AI Platform (Approuter)
Weaknesses CWE-807
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T00:15:40.747Z

Reserved: 2026-06-29T19:34:28.222Z

Link: CVE-2026-58239

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T01:30:04Z

Weaknesses
  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision