What is CVE-2026-58248?
A vulnerability has been identified in the Web Intelligence component of the SAP BusinessObjects Business Intelligence Platform. It allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references, leading to potential data exposure when the file is processed. Users are advised to apply the security patch released by SAP.
Azərbaycanca: SAP BusinessObjects Business Intelligence Platform-un Web Intelligence komponentində zəiflik aşkarlanıb. Bu boşluq aşağı səlahiyyətli istifadəçiyə xüsusi hazırlanmış zərərli elektron cədvəl faylı yükləməyə imkan verir. Fayl məlumat mənbəyi kimi emal edildikdə, xarici referanslar həll olunur və məxfi məlumatlar ifşa oluna bilər. İstifadəçilərə SAP tərəfindən buraxılmış təhlükəsizlik yamasını tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: shared vendor: SAP
FAQ2
Which component of the SAP BusinessObjects platform is affected by CVE-2026-58248?
This vulnerability is identified in the Web Intelligence component of the SAP BusinessObjects Business Intelligence Platform.
How can an attacker exploiting CVE-2026-58248 cause data exposure?
A low-privileged attacker can upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, these references are resolved, which can lead to the exposure of sensitive information.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.