# CVE-2026-58239

## Summary

- **CVE ID:** CVE-2026-58239
- **Severity:** LOW
- **CVSS Score:** 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **CWE:** CWE-807
- **Published:** Aug 11, 2026
- **Last Modified:** Aug 11, 2026

## Description

SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful exploitation could allow limited access to another tenant's information, resulting in a low impact on confidentiality. There is no impact on integrity and availability.

## Affected Products

- SAP_SE — SAP Business AI Platform (Approuter) (SAP Approuter node.js package < 23.0.0)

## References

- [CNA](https://me.sap.com/notes/3786038)
- [CNA](https://url.sap/sapsecuritypatchday)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.22%
- **EPSS Percentile:** 12.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._