Junglewise Threat Intelligence

CVE-2026-40128: SAP NetWeaver AS Java path traversal in Web Container

CVE-2026-40128 · Severity: critical · CVSS 9 · Published 2026-06-09

Technologies: SAP NetWeaver Application Server Java (Web Container). Vendors: SAP.

Executive brief

SAP NetWeaver Application Server Java, a foundational platform for many SAP business applications, contains a critical security flaw in its web handling component. An unauthenticated attacker can send a specially crafted login request to access or modify sensitive internal files and potentially crash the system. This could lead to the theft of corporate data, unauthorized changes to business records, or a total disruption of SAP-dependent business processes.

Technical details

A path traversal vulnerability (CWE-35) exists in the Web Container of SAP NetWeaver Application Server Java. The flaw is triggered via manipulated file inclusion parameters within an HTTP logon request. An unauthenticated remote attacker can exploit this to include and process local files, potentially leading to the disclosure of sensitive information, unauthorized data modification, or a denial-of-service (DoS) condition. While the attack vector is network-based and requires no privileges, the CVSS assessment indicates high complexity, likely due to specific configuration requirements or the need for precise parameter manipulation. SAP has released security note 3727078 to address this issue.

Affected products

  • SAP NetWeaver Application Server Java (Web Container)

Timeline

  • 2026-06-09: advisory: SAP Security Patch Day release
  • 2026-06-09: disclosed: NVD publication date

References