
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-58240 (dubbed "S4GET") is a critical authentication bypass vulnerability in SAP NetWeaver Message Server that allows unauthenticated attackers with network access to register unauthorized internal application server components. Affected versions include SAP NetWeaver (Message Server) KERNEL 9.16, 9.18, 9.19, and 9.20. The vulnerability was published on September 8, 2026, coinciding with SAP's September 2026 Security Patch Day. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Onapsis).
The root cause is classified as CWE-308 (Use of Single-factor Authentication): the SAP NetWeaver Message Server fails to sufficiently validate the authenticity of internal application server components during the registration process, relying on insufficient or single-factor checks. An unauthenticated attacker with network-level access to the Message Server port (typically TCP 3900 or similar internal ports) can send crafted registration requests to impersonate a legitimate application server component without providing valid credentials. No prior privileges or user interaction are required, and the attack complexity is low, making it highly automatable (GitHub Advisory, Dev.to writeup). A proof-of-concept was reportedly developed within 96 hours of patch day (SecurityBridge).
Successful exploitation allows an attacker to register a malicious component within the SAP NetWeaver application cluster, enabling unauthorized actions across the entire application environment. This results in high impact to confidentiality (access to sensitive business data), integrity (modification of application behavior and data), and availability (disruption of SAP services). The vulnerability can enable cluster-wide remote code execution, potentially affecting all application servers connected to the compromised Message Server, and poses significant risk of lateral movement within enterprise SAP landscapes (Onapsis, Dev.to writeup).
As of the time of reporting, no confirmed in-the-wild exploitation has been observed, and no public proof-of-concept exploit code has been officially released (GitHub Advisory). However, SecurityBridge reported that a PoC was developed within 96 hours of patch day, significantly raising the risk of imminent weaponization (SecurityBridge). The EPSS score is approximately 0.343% (28th percentile), and the vulnerability is rated as automatable with total technical impact by NVD SSVC analysis. The CVE is not currently listed in the CISA KEV catalog. Estimates suggest over 10,000 internet-facing SAP systems could be at risk (Undercode News).
ms_*.trc, dev_ms) showing registration of unknown or unexpected application server components; entries indicating new dispatcher registrations from unfamiliar hostnames or IP addresses.SAP has released patches via SAP Note 3759472, available through the SAP Support Portal (me.sap.com/notes/3759472), addressing affected kernel versions KERNEL 9.16, 9.18, 9.19, and 9.20. Organizations should apply the patch immediately as the highest priority action. As a network-level workaround, implement strict network segmentation to restrict access to the SAP Message Server ports exclusively to authorized application servers using firewall rules or network ACLs, preventing unauthenticated external access. Additionally, monitor Message Server component registration activities for any suspicious or unauthorized registrations (GitHub Advisory, SAP Patch Day, Onapsis).
The vulnerability received significant media and community attention as part of SAP's September 2026 Patch Day, which addressed 19–20 vulnerabilities total. Security researchers and outlets including BleepingComputer, SecurityWeek, The Hacker News, and Infosecurity Magazine highlighted the critical severity and potential for unauthenticated RCE across enterprise SAP landscapes (BleepingComputer, The Hacker News, Infosecurity Magazine). Onapsis published a dedicated threat advisory for CVE-2026-58240 (S4GET) and hosted a webinar on the September patch day vulnerabilities (Onapsis). SecurityBridge noted that a PoC was developed within 96 hours of patch release, and CERT-EU issued a security advisory covering the vulnerability (SecurityBridge, CERT-EU). The Stack Technology described the related SAP kernel flaws as potentially among the worst SAP has ever disclosed (The Stack).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"