PatchSiren cyber security CVE debrief
CVE-2026-58248 SAP_SE CVE debrief
CVE-2026-58248 is a medium-severity vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence). A low-privileged attacker can upload a specially crafted spreadsheet file containing malicious external references. When processed, the affected component resolves these references, potentially exposing sensitive server-side files within the resulting report. The vulnerability has a CVSS score of 6.5 and primarily affects confidentiality, with no impact on integrity and availability. Organizations should be aware of this vulnerability and take steps to mitigate it. Evidence is limited, and further verification is needed to determine the full scope of affected systems and potential mitigations. The CVE record was published on 2026-08-11T01:17:22.633Z and has not been modified since then.
- Vendor
- SAP_SE
- Product
- SAP BusinessObjects Business Intelligence
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-08-26
Who should care
Organizations using SAP BusinessObjects Business Intelligence Platform (Web Intelligence) should be aware of this vulnerability and take steps to mitigate it. This includes applying patches or updates provided by SAP, restricting access to sensitive server-side files and directories, and monitoring system logs for suspicious activity.
Technical summary
CVE-2026-58248 is a medium-severity vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) that allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When processed as a data source, the affected component resolves these references and potentially exposes the contents of sensitive server-side files within the resulting report. The vulnerability has a CVSS score of 6.5 and affects confidentiality, with no impact on integrity and availability.
Defensive priority
Organizations using SAP BusinessObjects Business Intelligence Platform (Web Intelligence) should prioritize patching to prevent potential data exposure.
Recommended defensive actions
- Apply patches or updates provided by SAP to address the vulnerability
- Restrict access to sensitive server-side files and directories
- Monitor system logs for suspicious activity related to file uploads and access
- Consider implementing additional security controls, such as input validation and sanitization
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record indicates a medium-severity vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allowing a low-privileged attacker to upload a malicious spreadsheet file, potentially exposing sensitive server-side files. Evidence is limited, and further verification is needed to determine the full scope of affected systems and potential mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-58248 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-58248
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-58248 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58248
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://me.sap.com/notes/3753141
-
Source reference
Unverified legacy reference
URL: https://url.sap/sapsecuritypatchday
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.