Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-58240: SAP NetWeaver Message Server lets unauthenticated users add fake components

CVE-2026-58240 · published 19 days ago
Summary

The Message Server in SAP NetWeaver does not verify that internal components are genuine when they register themselves. An attacker who can reach the server on the network could register a fake component and then act inside the system, potentially accessing or disrupting data and services. Limit network access to the Message Server, apply any vendor updates, and monitor for unexpected components to mitigate the risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
sap_se sap netweaver (message server) KERNEL 9.16
Original advisory text
Missing Authentication check in SAP NetWeaver (Message Server)
SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-308Use of Single-factor Authentication
Timeline
Published8 Sep 2026
Updated27 Sep 2026
First seen8 Sep 2026
Sources
CVE-2026-58240 · MITRE
Track software like this
Free during beta