PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-58248 SAP_SE CVE debrief

CVE-2026-58248 is a medium-severity vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence). A low-privileged attacker can upload a specially crafted spreadsheet file containing malicious external references. When processed, the affected component resolves these references, potentially exposing sensitive server-side files within the resulting report. The vulnerability has a CVSS score of 6.5 and primarily affects confidentiality, with no impact on integrity and availability. Organizations should be aware of this vulnerability and take steps to mitigate it. Evidence is limited, and further verification is needed to determine the full scope of affected systems and potential mitigations. The CVE record was published on 2026-08-11T01:17:22.633Z and has not been modified since then.

Vendor
SAP_SE
Product
SAP BusinessObjects Business Intelligence
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-08-26
Advisory published
2026-08-11
Advisory updated
2026-08-26

Who should care

Organizations using SAP BusinessObjects Business Intelligence Platform (Web Intelligence) should be aware of this vulnerability and take steps to mitigate it. This includes applying patches or updates provided by SAP, restricting access to sensitive server-side files and directories, and monitoring system logs for suspicious activity.

Technical summary

CVE-2026-58248 is a medium-severity vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) that allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When processed as a data source, the affected component resolves these references and potentially exposes the contents of sensitive server-side files within the resulting report. The vulnerability has a CVSS score of 6.5 and affects confidentiality, with no impact on integrity and availability.

Defensive priority

Organizations using SAP BusinessObjects Business Intelligence Platform (Web Intelligence) should prioritize patching to prevent potential data exposure.

Recommended defensive actions

  • Apply patches or updates provided by SAP to address the vulnerability
  • Restrict access to sensitive server-side files and directories
  • Monitor system logs for suspicious activity related to file uploads and access
  • Consider implementing additional security controls, such as input validation and sanitization
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record indicates a medium-severity vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allowing a low-privileged attacker to upload a malicious spreadsheet file, potentially exposing sensitive server-side files. Evidence is limited, and further verification is needed to determine the full scope of affected systems and potential mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-58248 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-58248

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-58248 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58248

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.