---
id: CVE-2026-58239
title: >-
  SAP Approuter does not sufficiently validate tenant context in inbound
  requests
summary: >-
  SAP Approuter does not sufficiently validate tenant context in inbound
  requests. An unauthenticated attacker could send specially crafted requests to
  spoof the tenant context under conditions not fully within their control.
  Successful ex…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-807
vendor: sap
product: approuter
affected:
  - approuter < 23.0.0
patched:
  - approuter 23.0.0
published: '2026-08-11'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:20:20.740'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-58239'
references:
  - url: 'https://me.sap.com/notes/3786038'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
epss: 0.0022
epssPercentile: 0.12769
ingestedAt: '2026-09-08T21:11:12.274Z'
---

## Overview

SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful exploitation could allow limited access to another tenant's information, resulting in a low impact on confidentiality. There is no impact on integrity and availability.

## Affected

- `approuter < 23.0.0`

## Remediation

Upgrade past the affected range:

- `approuter 23.0.0`
