CVE-2026-58240
SAP NetWeaver Application Server ABAP vulnerability analysis and mitigation

Overview

CVE-2026-58240 is a critical authentication bypass vulnerability in SAP NetWeaver Message Server that allows unauthenticated attackers with network access to register unauthorized internal application server components. Affected versions include SAP NetWeaver (Message Server) KERNEL 9.16, 9.18, 9.19, and 9.20. The vulnerability was published on September 8, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory).

Technical details

The root cause is insufficient validation of the authenticity of internal application server components during the registration process with the SAP NetWeaver Message Server, classified as CWE-308 (Use of Single-factor Authentication). Because the Message Server relies on weak or single-factor authentication for component registration, an unauthenticated attacker with network-level access to the Message Server port can register a malicious or unauthorized component without presenting valid credentials. No user interaction or elevated privileges are required, and the attack complexity is low, making this vulnerability highly automatable (GitHub Advisory, SAP Security Note).

Impact

Successful exploitation results in high impact to confidentiality, integrity, and availability of the affected SAP NetWeaver environment. An attacker who registers a malicious component can read sensitive business data processed by the application server, modify application behavior or intercept/manipulate communications between components, and disrupt service availability. Given SAP NetWeaver's role as a core enterprise integration platform, compromise could facilitate lateral movement into connected SAP systems and exposure of critical business data (GitHub Advisory).

Exploitability

As of the disclosure date (September 8, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is currently 0.0, reflecting low observed exploitation probability at time of publication. However, the vulnerability is rated as automatable by NVD SSVC analysis, meaning exploitation could be scripted without manual interaction. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities catalog.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible SAP NetWeaver Message Server instances running KERNEL 9.16, 9.18, 9.19, or 9.20 using network scanning tools (e.g., Nmap, Shodan) targeting the default Message Server port (typically TCP 3600 or 3900).
  2. Connect to Message Server: Establish a direct network connection to the SAP Message Server's internal registration port, which is normally intended only for trusted application server components.
  3. Register malicious component: Send a crafted registration request mimicking a legitimate SAP application server component. Due to insufficient authentication validation, the Message Server accepts the registration without verifying the component's authenticity.
  4. Perform unauthorized actions: Once registered as a trusted component, the attacker can intercept or manipulate inter-component communications, access sensitive data routed through the Message Server, inject malicious instructions into the application environment, or disrupt service availability by deregistering legitimate components (GitHub Advisory, SAP Security Note).

Indicators of compromise

  • Network: Unexpected inbound connections to the SAP Message Server internal port (TCP 3600/3900) from IP addresses not belonging to known application server hosts; unusual registration traffic patterns from external or untrusted network segments.
  • Logs: SAP Message Server logs showing registration of unknown or unexpected application server components; entries with unfamiliar system IDs or hostnames in the Message Server topology table.
  • Process/Application: Presence of unrecognized application server instances in the SAP system landscape directory or Message Server monitor (transaction SMMS); unexpected changes in load balancing or routing behavior within the SAP landscape.

Mitigation and workarounds

SAP has released a patch addressing this vulnerability, referenced in SAP Security Note 3759472, available via the SAP Support Portal. Organizations should apply the patch immediately for all affected KERNEL versions (9.16, 9.18, 9.19, 9.20). As a compensating control, implement strict network segmentation to restrict access to the SAP Message Server's internal registration port to only authorized application server IP addresses using firewalls or network ACLs. Additionally, monitor Message Server component registration activity for any unauthorized or unexpected registrations (SAP Security Note, SAP Patch Day).

Community reactions

The vulnerability received coverage across multiple security news outlets following SAP's September 2026 Patch Day, including SecurityOnline, GBHackers, CyberSecurityNews, and Onapsis, which highlighted it as one of the critical flaws addressed in the monthly release. SecurityBridge and Cryptika also published analyses of the September 2026 SAP patch cycle, noting the authentication bypass risk in NetWeaver Message Server. Social media activity on Mastodon included posts from security-focused accounts flagging the critical severity rating (SecurityOnline, Onapsis Blog, SecurityBridge).

Additional resources


SourceThis report was generated using AI

Related SAP NetWeaver Application Server ABAP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44756CRITICAL10
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesSep 08, 2026
CVE-2026-58240CRITICAL9.8
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_java
NoNoSep 08, 2026
CVE-2026-66767HIGH7.7
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesSep 08, 2026
CVE-2026-66779MEDIUM6.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoNoAug 11, 2026
CVE-2026-58236MEDIUM5.5
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesAug 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management