CVE-2026-58240
SAP NetWeaver Application Server ABAP Analisi e mitigazione delle vulnerabilità

Panoramica

CVE-2026-58240 is a critical authentication bypass vulnerability in SAP NetWeaver Message Server that allows unauthenticated attackers with network access to register unauthorized internal application server components. Affected versions include SAP NetWeaver (Message Server) KERNEL 9.16, 9.18, 9.19, and 9.20. The vulnerability was published on September 8, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory).

Dettagli tecnici

The root cause is insufficient validation of the authenticity of internal application server components during the registration process with the SAP NetWeaver Message Server, classified as CWE-308 (Use of Single-factor Authentication). Because the Message Server relies on weak or single-factor authentication for component registration, an unauthenticated attacker with network-level access to the Message Server port can register a malicious or unauthorized component without presenting valid credentials. No user interaction or elevated privileges are required, and the attack complexity is low, making this vulnerability highly automatable (GitHub Advisory, SAP Security Note).

Impatto

Successful exploitation results in high impact to confidentiality, integrity, and availability of the affected SAP NetWeaver environment. An attacker who registers a malicious component can read sensitive business data processed by the application server, modify application behavior or intercept/manipulate communications between components, and disrupt service availability. Given SAP NetWeaver's role as a core enterprise integration platform, compromise could facilitate lateral movement into connected SAP systems and exposure of critical business data (GitHub Advisory).

Sfruttabilità

As of the disclosure date (September 8, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is currently 0.0, reflecting low observed exploitation probability at time of publication. However, the vulnerability is rated as automatable by NVD SSVC analysis, meaning exploitation could be scripted without manual interaction. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities catalog.

Passaggi di sfruttamento

  1. Reconnaissance: Identify internet-facing or network-accessible SAP NetWeaver Message Server instances running KERNEL 9.16, 9.18, 9.19, or 9.20 using network scanning tools (e.g., Nmap, Shodan) targeting the default Message Server port (typically TCP 3600 or 3900).
  2. Connect to Message Server: Establish a direct network connection to the SAP Message Server's internal registration port, which is normally intended only for trusted application server components.
  3. Register malicious component: Send a crafted registration request mimicking a legitimate SAP application server component. Due to insufficient authentication validation, the Message Server accepts the registration without verifying the component's authenticity.
  4. Perform unauthorized actions: Once registered as a trusted component, the attacker can intercept or manipulate inter-component communications, access sensitive data routed through the Message Server, inject malicious instructions into the application environment, or disrupt service availability by deregistering legitimate components (GitHub Advisory, SAP Security Note).

Indicatori di compromesso

  • Network: Unexpected inbound connections to the SAP Message Server internal port (TCP 3600/3900) from IP addresses not belonging to known application server hosts; unusual registration traffic patterns from external or untrusted network segments.
  • Logs: SAP Message Server logs showing registration of unknown or unexpected application server components; entries with unfamiliar system IDs or hostnames in the Message Server topology table.
  • Process/Application: Presence of unrecognized application server instances in the SAP system landscape directory or Message Server monitor (transaction SMMS); unexpected changes in load balancing or routing behavior within the SAP landscape.

Mitigazione e soluzioni alternative

SAP has released a patch addressing this vulnerability, referenced in SAP Security Note 3759472, available via the SAP Support Portal. Organizations should apply the patch immediately for all affected KERNEL versions (9.16, 9.18, 9.19, 9.20). As a compensating control, implement strict network segmentation to restrict access to the SAP Message Server's internal registration port to only authorized application server IP addresses using firewalls or network ACLs. Additionally, monitor Message Server component registration activity for any unauthorized or unexpected registrations (SAP Security Note, SAP Patch Day).

Reazioni della comunità

The vulnerability received coverage across multiple security news outlets following SAP's September 2026 Patch Day, including SecurityOnline, GBHackers, CyberSecurityNews, and Onapsis, which highlighted it as one of the critical flaws addressed in the monthly release. SecurityBridge and Cryptika also published analyses of the September 2026 SAP patch cycle, noting the authentication bypass risk in NetWeaver Message Server. Social media activity on Mastodon included posts from security-focused accounts flagging the critical severity rating (SecurityOnline, Onapsis Blog, SecurityBridge).

Risorse aggiuntive


FonteQuesto report è stato generato utilizzando l'intelligenza artificiale

Imparentato SAP NetWeaver Application Server ABAP Vulnerabilità:

CVE ID

Severità

Punteggio

Tecnologie

Nome del componente

Exploit CISA KEV

Ha la correzione

Data di pubblicazione

CVE-2026-44756CRITICAL10
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoSep 08, 2026
CVE-2026-58240CRITICAL9.8
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_java
NoNoSep 08, 2026
CVE-2026-66767HIGH7.7
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoSep 08, 2026
CVE-2026-66779MEDIUM6.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoNoAug 11, 2026
CVE-2026-58236MEDIUM5.5
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoAug 11, 2026

Valutazione gratuita delle vulnerabilità

Benchmark della tua posizione di sicurezza del cloud

Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.

Richiedi valutazione

Richiedi una demo personalizzata

Pronti a vedere Wiz in azione?

"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
David EstlickCISO (CISO)
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
Adam FletcherResponsabile della sicurezza
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."
Greg PoniatowskiResponsabile della gestione delle minacce e delle vulnerabilità