
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-40128 is a path traversal vulnerability in SAP NetWeaver Application Server Java (Web Container) that allows unauthenticated attackers to craft malicious HTTP logon requests that manipulate file inclusion parameters, enabling traversal of the file system and processing of arbitrary files. The vulnerability affects SAP NetWeaver AS Java, specifically ENGINEAPI version 7.50, and was published on June 9, 2026. It carries a CVSS v3.1 base score of 9.0 (Critical) with a changed scope, reflecting potential impact beyond the directly vulnerable component (GitHub Advisory, Feedly).
The root cause is classified as CWE-35 (Path Traversal: '.../...//'), where the Web Container fails to properly neutralize doubled triple-dot-slash sequences in file inclusion parameters of HTTP logon requests, allowing attackers to resolve paths outside the intended restricted directory (GitHub Advisory). An unauthenticated remote attacker can exploit this by sending a specially crafted HTTP logon request with manipulated file inclusion parameters containing path traversal sequences, causing the server to process files outside the intended directory. No authentication or user interaction is required, though the attack complexity is rated High, suggesting some precondition or environmental factor must be met for reliable exploitation (GitHub Advisory, Feedly).
Successful exploitation can result in high impact to confidentiality, integrity, and availability — an attacker may read sensitive files from the local system, modify files, or render parts of the system unavailable. The vulnerability's changed scope means impacts can extend beyond the SAP Web Container itself to other components on the host system. Given SAP NetWeaver's role as a core enterprise integration platform, exploitation could expose business-critical data, configuration files, credentials, or disrupt mission-critical ERP operations (GitHub Advisory, Feedly).
/irj/portal or similar logon URLs exposed by the AS Java Web Container)..../...// patterns) within file inclusion parameters to escape the restricted directory context..../...//, ..%2f, or encoded variants in file inclusion parameters; unexpected outbound connections from the SAP server.SAP addressed this vulnerability as part of the June 2026 Security Patch Day; the relevant fix is documented in SAP Security Note 3727078, available to customers via the SAP Support Portal (GitHub Advisory, SAP Patch Day). Organizations should apply the patch immediately, prioritizing internet-facing SAP NetWeaver AS Java instances. As interim mitigations, implement strict input validation on file inclusion parameters, apply network-level access controls to restrict exposure of SAP logon endpoints to trusted networks only, and monitor for path traversal patterns in HTTP request logs (Feedly).
The vulnerability was covered as part of SAP's June 2026 Security Patch Day, which received broad industry attention due to multiple critical-severity fixes. Security outlets including BleepingComputer, SecurityWeek, The Hacker News, and Onapsis highlighted the patch day's significance, noting four critical vulnerabilities including CVE-2026-40128 (BleepingComputer, SecurityWeek, The Hacker News). Government cybersecurity agencies including Belgium's CCB and Singapore's CSA issued advisories urging prompt patching (Feedly, CSA Singapore). Community discussion on Reddit and social media reflected concern about the breadth of SAP's critical patches in this cycle.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."