CVE-2026-58240
Received Received - Intake

SAP NetWeaver Message Server Component Registration Spoofing

Vulnerability report for CVE-2026-58240, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: SAP SE

Description

SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap netweaver_message_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-308 The product uses an authentication algorithm that uses a single factor (e.g., a password) in a security context that should require more than one factor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SAP NetWeaver Message Server does not properly verify the authenticity of internal application server components when they register. An attacker without authentication but with network access could exploit this to register an unauthorized component and perform unauthorized actions, potentially compromising the system's confidentiality, integrity, and availability.

Detection Guidance

Detecting this vulnerability requires monitoring SAP NetWeaver Message Server for unauthorized component registrations. Check server logs for unexpected registration attempts or components. Use network monitoring tools to inspect traffic to the message server port (default 3900) for anomalies. SAP provides tools like SAPControl or SAP Host Agent for system checks.

Impact Analysis

This vulnerability could allow an attacker to gain unauthorized access to your SAP system, manipulate data, disrupt services, or steal sensitive information. It may lead to system downtime, data breaches, or compliance violations depending on the data processed by the affected system.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate GDPR (data protection) or HIPAA (health information privacy) requirements. Non-compliance could result in legal penalties, fines, or reputational damage depending on the data exposed.

Mitigation Strategies

Apply the official SAP security note 3759472 to patch the vulnerability. Ensure network segmentation restricts access to the SAP NetWeaver Message Server. Monitor application server registrations for unauthorized components.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58240. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart