Tenant Context Spoofing in SAP Approuter
CVE-2026-58239
3.7LOW
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-58239?
SAP Approuter has a vulnerability that arises from inadequate validation of tenant context in incoming requests. An attacker without authentication can exploit this flaw by sending specifically crafted requests, which may simulate a tenant's context. This could lead to unauthorized access to another tenant's data, primarily affecting confidentiality. Although the access is limited, it poses a security risk that necessitates attention and remediation.
Affected Version(s)
SAP Business AI Platform (Approuter) SAP Approuter node.js package < 23.0.0