Vulnerability in SAP BusinessObjects Business Intelligence Platform Exposes Sensitive Data
CVE-2026-58248
6.5MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-58248?
The SAP BusinessObjects Business Intelligence Platform, specifically the Web Intelligence component, is susceptible to a vulnerability that permits low-privileged attackers to upload maliciously crafted spreadsheet files. These files contain external references that, when processed, lead to the inadvertent exposure of sensitive server-side files within generated reports. This flaw compromises the confidentiality of critical data without affecting the integrity or availability of the system.
Affected Version(s)
SAP BusinessObjects Business Intelligence ENTERPRISE 430
SAP BusinessObjects Business Intelligence 2025
SAP BusinessObjects Business Intelligence 2027