CVE-2026-58240
SAP NetWeaver Application Server ABAP Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-58240 is a critical authentication bypass vulnerability in SAP NetWeaver Message Server that allows unauthenticated attackers with network access to register unauthorized internal application server components. Affected versions include SAP NetWeaver (Message Server) KERNEL 9.16, 9.18, 9.19, and 9.20. The vulnerability was published on September 8, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory).

Detalhes técnicos

The root cause is insufficient validation of the authenticity of internal application server components during the registration process with the SAP NetWeaver Message Server, classified as CWE-308 (Use of Single-factor Authentication). Because the Message Server relies on weak or single-factor authentication for component registration, an unauthenticated attacker with network-level access to the Message Server port can register a malicious or unauthorized component without presenting valid credentials. No user interaction or elevated privileges are required, and the attack complexity is low, making this vulnerability highly automatable (GitHub Advisory, SAP Security Note).

Impacto

Successful exploitation results in high impact to confidentiality, integrity, and availability of the affected SAP NetWeaver environment. An attacker who registers a malicious component can read sensitive business data processed by the application server, modify application behavior or intercept/manipulate communications between components, and disrupt service availability. Given SAP NetWeaver's role as a core enterprise integration platform, compromise could facilitate lateral movement into connected SAP systems and exposure of critical business data (GitHub Advisory).

Exploração

As of the disclosure date (September 8, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is currently 0.0, reflecting low observed exploitation probability at time of publication. However, the vulnerability is rated as automatable by NVD SSVC analysis, meaning exploitation could be scripted without manual interaction. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities catalog.

Etapas de exploração

  1. Reconnaissance: Identify internet-facing or network-accessible SAP NetWeaver Message Server instances running KERNEL 9.16, 9.18, 9.19, or 9.20 using network scanning tools (e.g., Nmap, Shodan) targeting the default Message Server port (typically TCP 3600 or 3900).
  2. Connect to Message Server: Establish a direct network connection to the SAP Message Server's internal registration port, which is normally intended only for trusted application server components.
  3. Register malicious component: Send a crafted registration request mimicking a legitimate SAP application server component. Due to insufficient authentication validation, the Message Server accepts the registration without verifying the component's authenticity.
  4. Perform unauthorized actions: Once registered as a trusted component, the attacker can intercept or manipulate inter-component communications, access sensitive data routed through the Message Server, inject malicious instructions into the application environment, or disrupt service availability by deregistering legitimate components (GitHub Advisory, SAP Security Note).

Indicadores de compromisso

  • Network: Unexpected inbound connections to the SAP Message Server internal port (TCP 3600/3900) from IP addresses not belonging to known application server hosts; unusual registration traffic patterns from external or untrusted network segments.
  • Logs: SAP Message Server logs showing registration of unknown or unexpected application server components; entries with unfamiliar system IDs or hostnames in the Message Server topology table.
  • Process/Application: Presence of unrecognized application server instances in the SAP system landscape directory or Message Server monitor (transaction SMMS); unexpected changes in load balancing or routing behavior within the SAP landscape.

Mitigação e soluções alternativas

SAP has released a patch addressing this vulnerability, referenced in SAP Security Note 3759472, available via the SAP Support Portal. Organizations should apply the patch immediately for all affected KERNEL versions (9.16, 9.18, 9.19, 9.20). As a compensating control, implement strict network segmentation to restrict access to the SAP Message Server's internal registration port to only authorized application server IP addresses using firewalls or network ACLs. Additionally, monitor Message Server component registration activity for any unauthorized or unexpected registrations (SAP Security Note, SAP Patch Day).

Reações da comunidade

The vulnerability received coverage across multiple security news outlets following SAP's September 2026 Patch Day, including SecurityOnline, GBHackers, CyberSecurityNews, and Onapsis, which highlighted it as one of the critical flaws addressed in the monthly release. SecurityBridge and Cryptika also published analyses of the September 2026 SAP patch cycle, noting the authentication bypass risk in NetWeaver Message Server. Social media activity on Mastodon included posts from security-focused accounts flagging the critical severity rating (SecurityOnline, Onapsis Blog, SecurityBridge).

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Relacionado SAP NetWeaver Application Server ABAP Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-44756CRITICAL10
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NãoSimSep 08, 2026
CVE-2026-58240CRITICAL9.8
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NãoNãoSep 08, 2026
CVE-2026-66767HIGH7.7
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NãoSimSep 08, 2026
CVE-2026-66779MEDIUM6.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NãoNãoAug 11, 2026
CVE-2026-58236MEDIUM5.5
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NãoSimAug 11, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades