CVE-2026-58240: 
SAP NetWeaver Application Server ABAP 脆弱性の分析と軽減

概要

CVE-2026-58240 (dubbed "S4GET") is a critical authentication bypass vulnerability in SAP NetWeaver Message Server that allows unauthenticated attackers with network access to register unauthorized internal application server components. Affected versions include SAP NetWeaver (Message Server) KERNEL 9.16, 9.18, 9.19, and 9.20. The vulnerability was published on September 8, 2026, coinciding with SAP's September 2026 Security Patch Day. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Onapsis).

技術的な詳細

The root cause is classified as CWE-308 (Use of Single-factor Authentication): the SAP NetWeaver Message Server fails to sufficiently validate the authenticity of internal application server components during the registration process, relying on insufficient or single-factor checks. An unauthenticated attacker with network-level access to the Message Server port (typically TCP 3900 or similar internal ports) can send crafted registration requests to impersonate a legitimate application server component without providing valid credentials. No prior privileges or user interaction are required, and the attack complexity is low, making it highly automatable (GitHub Advisory, Dev.to writeup). A proof-of-concept was reportedly developed within 96 hours of patch day (SecurityBridge).

影響

Successful exploitation allows an attacker to register a malicious component within the SAP NetWeaver application cluster, enabling unauthorized actions across the entire application environment. This results in high impact to confidentiality (access to sensitive business data), integrity (modification of application behavior and data), and availability (disruption of SAP services). The vulnerability can enable cluster-wide remote code execution, potentially affecting all application servers connected to the compromised Message Server, and poses significant risk of lateral movement within enterprise SAP landscapes (Onapsis, Dev.to writeup).

エクスプロイト可能性

As of the time of reporting, no confirmed in-the-wild exploitation has been observed, and no public proof-of-concept exploit code has been officially released (GitHub Advisory). However, SecurityBridge reported that a PoC was developed within 96 hours of patch day, significantly raising the risk of imminent weaponization (SecurityBridge). The EPSS score is approximately 0.343% (28th percentile), and the vulnerability is rated as automatable with total technical impact by NVD SSVC analysis. The CVE is not currently listed in the CISA KEV catalog. Estimates suggest over 10,000 internet-facing SAP systems could be at risk (Undercode News).

エクスプロイテーションのステップ

  1. Reconnaissance: Use tools such as Shodan or Censys to identify internet-facing SAP NetWeaver systems running Message Server on affected kernel versions (KERNEL 9.16, 9.18, 9.19, 9.20). Look for exposed Message Server ports (commonly TCP 3900 for HTTP or TCP 39NN for internal communication).
  2. Network Access: Establish network connectivity to the target SAP Message Server port. If the port is not directly internet-exposed, pivot through a compromised network segment with access to the SAP internal network.
  3. Craft Registration Request: Construct a malicious application server registration request that mimics the internal SAP ABAP dispatcher registration protocol, exploiting the lack of strong authentication validation in the Message Server.
  4. Register Unauthorized Component: Send the crafted request to the Message Server. Due to insufficient authenticity validation (CWE-308), the server accepts the registration of the attacker-controlled component as a legitimate application server node.
  5. Perform Unauthorized Actions: Once registered as a trusted component, issue commands or intercept/manipulate traffic within the SAP cluster, potentially achieving cluster-wide remote code execution, data exfiltration, or service disruption (Dev.to writeup, Onapsis).

妥協の兆候

  • Network: Unexpected inbound connections to SAP Message Server ports (e.g., TCP 3900, 3600, or kernel-specific ports) from unauthorized IP addresses or external sources; unusual registration traffic patterns on internal SAP network segments.
  • Logs: SAP Message Server logs (ms_*.trc, dev_ms) showing registration of unknown or unexpected application server components; entries indicating new dispatcher registrations from unfamiliar hostnames or IP addresses.
  • Process/Application: Unexpected application server instances appearing in SAP system monitoring (SM51, SM50) that are not part of the known landscape; anomalous work process activity originating from newly registered components.
  • File System: Unexpected files or scripts written to SAP instance directories by processes associated with newly registered components (Onapsis, SecurityBridge).

軽減策と回避策

SAP has released patches via SAP Note 3759472, available through the SAP Support Portal (me.sap.com/notes/3759472), addressing affected kernel versions KERNEL 9.16, 9.18, 9.19, and 9.20. Organizations should apply the patch immediately as the highest priority action. As a network-level workaround, implement strict network segmentation to restrict access to the SAP Message Server ports exclusively to authorized application servers using firewall rules or network ACLs, preventing unauthenticated external access. Additionally, monitor Message Server component registration activities for any suspicious or unauthorized registrations (GitHub Advisory, SAP Patch Day, Onapsis).

コミュニティの反応

The vulnerability received significant media and community attention as part of SAP's September 2026 Patch Day, which addressed 19–20 vulnerabilities total. Security researchers and outlets including BleepingComputer, SecurityWeek, The Hacker News, and Infosecurity Magazine highlighted the critical severity and potential for unauthenticated RCE across enterprise SAP landscapes (BleepingComputer, The Hacker News, Infosecurity Magazine). Onapsis published a dedicated threat advisory for CVE-2026-58240 (S4GET) and hosted a webinar on the September patch day vulnerabilities (Onapsis). SecurityBridge noted that a PoC was developed within 96 hours of patch release, and CERT-EU issued a security advisory covering the vulnerability (SecurityBridge, CERT-EU). The Stack Technology described the related SAP kernel flaws as potentially among the worst SAP has ever disclosed (The Stack).

関連情報


ソース: このレポートは AI を使用して生成されました

関連 SAP NetWeaver Application Server ABAP 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-44756CRITICAL10
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
いいえはいSep 08, 2026
CVE-2026-58240CRITICAL9.8
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_java
いいえはいSep 08, 2026
CVE-2026-66767HIGH7.7
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
いいえはいSep 08, 2026
CVE-2026-66779MEDIUM6.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
いいえいいえAug 11, 2026
CVE-2026-58236MEDIUM5.5
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
いいえはいAug 11, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者