CVE-2026-58240
SAP NetWeaver Application Server ABAP Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-58240 is a critical authentication bypass vulnerability in SAP NetWeaver Message Server that allows unauthenticated attackers with network access to register unauthorized internal application server components. Affected versions include SAP NetWeaver (Message Server) KERNEL 9.16, 9.18, 9.19, and 9.20. The vulnerability was published on September 8, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory).

Détails techniques

The root cause is insufficient validation of the authenticity of internal application server components during the registration process with the SAP NetWeaver Message Server, classified as CWE-308 (Use of Single-factor Authentication). Because the Message Server relies on weak or single-factor authentication for component registration, an unauthenticated attacker with network-level access to the Message Server port can register a malicious or unauthorized component without presenting valid credentials. No user interaction or elevated privileges are required, and the attack complexity is low, making this vulnerability highly automatable (GitHub Advisory, SAP Security Note).

Impact

Successful exploitation results in high impact to confidentiality, integrity, and availability of the affected SAP NetWeaver environment. An attacker who registers a malicious component can read sensitive business data processed by the application server, modify application behavior or intercept/manipulate communications between components, and disrupt service availability. Given SAP NetWeaver's role as a core enterprise integration platform, compromise could facilitate lateral movement into connected SAP systems and exposure of critical business data (GitHub Advisory).

Exploitabilité

As of the disclosure date (September 8, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is currently 0.0, reflecting low observed exploitation probability at time of publication. However, the vulnerability is rated as automatable by NVD SSVC analysis, meaning exploitation could be scripted without manual interaction. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities catalog.

Étapes d’exploitation

  1. Reconnaissance: Identify internet-facing or network-accessible SAP NetWeaver Message Server instances running KERNEL 9.16, 9.18, 9.19, or 9.20 using network scanning tools (e.g., Nmap, Shodan) targeting the default Message Server port (typically TCP 3600 or 3900).
  2. Connect to Message Server: Establish a direct network connection to the SAP Message Server's internal registration port, which is normally intended only for trusted application server components.
  3. Register malicious component: Send a crafted registration request mimicking a legitimate SAP application server component. Due to insufficient authentication validation, the Message Server accepts the registration without verifying the component's authenticity.
  4. Perform unauthorized actions: Once registered as a trusted component, the attacker can intercept or manipulate inter-component communications, access sensitive data routed through the Message Server, inject malicious instructions into the application environment, or disrupt service availability by deregistering legitimate components (GitHub Advisory, SAP Security Note).

Indicateurs de compromis

  • Network: Unexpected inbound connections to the SAP Message Server internal port (TCP 3600/3900) from IP addresses not belonging to known application server hosts; unusual registration traffic patterns from external or untrusted network segments.
  • Logs: SAP Message Server logs showing registration of unknown or unexpected application server components; entries with unfamiliar system IDs or hostnames in the Message Server topology table.
  • Process/Application: Presence of unrecognized application server instances in the SAP system landscape directory or Message Server monitor (transaction SMMS); unexpected changes in load balancing or routing behavior within the SAP landscape.

Atténuation et solutions de contournement

SAP has released a patch addressing this vulnerability, referenced in SAP Security Note 3759472, available via the SAP Support Portal. Organizations should apply the patch immediately for all affected KERNEL versions (9.16, 9.18, 9.19, 9.20). As a compensating control, implement strict network segmentation to restrict access to the SAP Message Server's internal registration port to only authorized application server IP addresses using firewalls or network ACLs. Additionally, monitor Message Server component registration activity for any unauthorized or unexpected registrations (SAP Security Note, SAP Patch Day).

Réactions de la communauté

The vulnerability received coverage across multiple security news outlets following SAP's September 2026 Patch Day, including SecurityOnline, GBHackers, CyberSecurityNews, and Onapsis, which highlighted it as one of the critical flaws addressed in the monthly release. SecurityBridge and Cryptika also published analyses of the September 2026 SAP patch cycle, noting the authentication bypass risk in NetWeaver Message Server. Social media activity on Mastodon included posts from security-focused accounts flagging the critical severity rating (SecurityOnline, Onapsis Blog, SecurityBridge).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté SAP NetWeaver Application Server ABAP Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-44756CRITICAL10
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NonOuiSep 08, 2026
CVE-2026-58240CRITICAL9.8
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NonNonSep 08, 2026
CVE-2026-66767HIGH7.7
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NonOuiSep 08, 2026
CVE-2026-66779MEDIUM6.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NonNonAug 11, 2026
CVE-2026-58236MEDIUM5.5
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NonOuiAug 11, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités