Executive brief
SAP Approuter is a routing and authentication service used to manage access to SAP applications in cloud environments. An unauthenticated attacker can send crafted requests to impersonate a different tenant and gain limited visibility into another organization's data. The vulnerability has a low impact on data confidentiality but does not affect system availability or data integrity.
Technical details
The vulnerability is a tenant context validation bypass in SAP Approuter. The root cause is insufficient validation of tenant context in inbound requests, allowing an attacker to spoof the tenant identifier under specific conditions. An unauthenticated attacker can send specially crafted requests over the network to trigger this flaw, potentially accessing information belonging to other tenants. Exploitation requires conditions not fully within the attacker's control, limiting the practical impact. SAP released a patch on 2026-08-11 as part of its Security Patch Day.
Affected products
- SAP Approuter
Timeline
- 2026-08-11: disclosed