CVE-2026-58234
Received Received - Intake

Privileged User-Induced DoS in SAP Process Integration SOAP Adapter

Vulnerability report for CVE-2026-58234, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: SAP SE

Description

SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with no impact on confidentiality and integrity.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap process_integration *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-776 The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in SAP Process Integration (SOAP Adapter) allows a privileged user to send crafted requests with deeply nested entity definitions. This can temporarily increase processor load and reduce system responsiveness. It has low impact on availability but no effect on confidentiality or integrity.

Detection Guidance

Detection may involve monitoring for unusual processor load spikes or degraded system responsiveness during SOAP request processing. Check SAP logs for requests with deeply nested entity definitions. Use system monitoring tools like SAP Solution Manager or OS-level commands (e.g., top, htop) to observe CPU usage patterns.

Impact Analysis

The main impact is degraded system performance due to increased processor load. This could slow down operations but does not expose sensitive data or allow unauthorized changes. Only privileged users can exploit it.

Compliance Impact

This vulnerability does not directly impact confidentiality or integrity, so it likely poses minimal compliance risk for standards like GDPR or HIPAA. However, degraded system performance could indirectly affect service availability, which may need review.

Mitigation Strategies

Apply SAP security notes and updates as recommended in SAP Note 3736494 to address the issue with deeply nested entity definitions in the SOAP Adapter.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58234. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart