CVE-2026-40128
SAP NetWeaver Application Server Java vulnerability analysis and mitigation

Overview

CVE-2026-40128 is a path traversal vulnerability in SAP NetWeaver Application Server Java (Web Container) that allows unauthenticated attackers to craft malicious HTTP logon requests that manipulate file inclusion parameters, enabling traversal of the file system and processing of arbitrary files. The vulnerability affects SAP NetWeaver AS Java, specifically ENGINEAPI version 7.50, and was published on June 9, 2026. It carries a CVSS v3.1 base score of 9.0 (Critical) with a changed scope, reflecting potential impact beyond the directly vulnerable component (GitHub Advisory, Feedly).

Technical details

The root cause is classified as CWE-35 (Path Traversal: '.../...//'), where the Web Container fails to properly neutralize doubled triple-dot-slash sequences in file inclusion parameters of HTTP logon requests, allowing attackers to resolve paths outside the intended restricted directory (GitHub Advisory). An unauthenticated remote attacker can exploit this by sending a specially crafted HTTP logon request with manipulated file inclusion parameters containing path traversal sequences, causing the server to process files outside the intended directory. No authentication or user interaction is required, though the attack complexity is rated High, suggesting some precondition or environmental factor must be met for reliable exploitation (GitHub Advisory, Feedly).

Impact

Successful exploitation can result in high impact to confidentiality, integrity, and availability — an attacker may read sensitive files from the local system, modify files, or render parts of the system unavailable. The vulnerability's changed scope means impacts can extend beyond the SAP Web Container itself to other components on the host system. Given SAP NetWeaver's role as a core enterprise integration platform, exploitation could expose business-critical data, configuration files, credentials, or disrupt mission-critical ERP operations (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing SAP NetWeaver Application Server Java instances, particularly those exposing HTTP logon endpoints, using tools like Shodan or Censys targeting SAP-specific banners or ports (e.g., 50000/50001).
  2. Identify target endpoint: Locate the HTTP logon endpoint of the SAP Web Container (typically /irj/portal or similar logon URLs exposed by the AS Java Web Container).
  3. Craft malicious request: Construct an HTTP logon request that includes path traversal sequences (e.g., .../...// patterns) within file inclusion parameters to escape the restricted directory context.
  4. Trigger file inclusion: Submit the crafted request to the target server; if successful, the server processes the attacker-specified file from an arbitrary location on the local file system.
  5. Achieve objective: Depending on the file processed, the attacker may read sensitive configuration files (e.g., credentials, keys), modify accessible files, or cause a denial of service by including files that crash the application (GitHub Advisory, Feedly).

Indicators of compromise

  • Network: Unusual HTTP requests to SAP NetWeaver AS Java logon endpoints containing path traversal patterns such as .../...//, ..%2f, or encoded variants in file inclusion parameters; unexpected outbound connections from the SAP server.
  • Logs: SAP Web Container access logs showing HTTP logon requests with anomalous parameter values containing traversal sequences; repeated 200 or 500 responses to malformed logon requests from external IPs.
  • File System: Unexpected access to sensitive files outside the SAP installation directory (e.g., OS configuration files, credential stores) reflected in file access audit logs.
  • Process: Unusual file read/write operations by the SAP Java process on files outside the expected application directories (GitHub Advisory, Feedly).

Mitigation and workarounds

SAP addressed this vulnerability as part of the June 2026 Security Patch Day; the relevant fix is documented in SAP Security Note 3727078, available to customers via the SAP Support Portal (GitHub Advisory, SAP Patch Day). Organizations should apply the patch immediately, prioritizing internet-facing SAP NetWeaver AS Java instances. As interim mitigations, implement strict input validation on file inclusion parameters, apply network-level access controls to restrict exposure of SAP logon endpoints to trusted networks only, and monitor for path traversal patterns in HTTP request logs (Feedly).

Community reactions

The vulnerability was covered as part of SAP's June 2026 Security Patch Day, which received broad industry attention due to multiple critical-severity fixes. Security outlets including BleepingComputer, SecurityWeek, The Hacker News, and Onapsis highlighted the patch day's significance, noting four critical vulnerabilities including CVE-2026-40128 (BleepingComputer, SecurityWeek, The Hacker News). Government cybersecurity agencies including Belgium's CCB and Singapore's CSA issued advisories urging prompt patching (Feedly, CSA Singapore). Community discussion on Reddit and social media reflected concern about the breadth of SAP's critical patches in this cycle.

Additional resources


SourceThis report was generated using AI

Related SAP NetWeaver Application Server Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-42944CRITICAL10
  • SAP NetWeaver Application Server Java logoSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoYesSep 09, 2025
CVE-2026-40128CRITICAL9
  • SAP NetWeaver Application Server Java logoSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoYesJun 09, 2026
CVE-2026-27674MEDIUM6.1
  • SAP NetWeaver Application Server Java logoSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoYesApr 14, 2026
CVE-2025-42926MEDIUM5.3
  • SAP NetWeaver Application Server Java logoSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoYesSep 09, 2025
CVE-2026-23686LOW3.4
  • SAP NetWeaver Application Server Java logoSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoYesFeb 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management