CVE-2026-58240
9.8SAP_SE · SAP NetWeaver (Message Server)
A vulnerability in the SAP NetWeaver Message Server allows unauthenticated attackers to register unauthorized application server components.
Executive summary
A critical authentication failure in the SAP NetWeaver Message Server enables unauthenticated attackers to register malicious components and compromise the application environment.
Vulnerability
The Message Server fails to validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access can exploit this to register an unauthorized component, effectively bypassing authentication controls to perform unauthorized actions.
Business impact
This vulnerability is assigned a CVSS score of 9.8, indicating the highest level of risk. An attacker can gain control over the application environment, potentially leading to unauthorized data access, service disruption, or full system takeover. Given the central role of SAP NetWeaver in enterprise operations, this represents a significant threat to business continuity and data integrity.
Remediation
Immediate Action: Apply the security updates provided in SAP Note 3759472 immediately to address the authentication registration flaw.
Proactive Monitoring: Review Message Server logs for anomalous registration events or unexpected component connections that deviate from established baselines.
Compensating Controls: Ensure that the SAP Message Server is not exposed to the public internet and restrict access to the service port to only authorized application server hosts.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
Organizations running SAP NetWeaver must prioritize the application of the patches specified in SAP Note 3759472. Given the critical nature of the flaw and the ease of exploitation for actors with network access, timely remediation is essential to prevent potential system compromise.
More SAP_SE CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Analyst report updated
- Published in the daily brief critical section