Junglewise Threat Intelligence

CVE-2026-58240: SAP NetWeaver Message Server authentication bypass in component registration

CVE-2026-58240 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Technologies: SAP NetWeaver. Vendors: SAP.

Executive brief

SAP NetWeaver Message Server is a central communication hub used by SAP enterprise applications to route messages and manage server instances. This vulnerability allows an unauthenticated attacker with network access to register unauthorized application server components, potentially gaining control over system operations. An exploit could result in data breaches, system compromise, and service disruption across the entire SAP environment.

Technical details

The vulnerability is an authentication bypass in the component registration mechanism of SAP NetWeaver Message Server. The service does not sufficiently validate the authenticity of internal application server components during registration, allowing an unauthenticated attacker with network access to register malicious components without proper authorization. Once registered, an unauthorized component can perform arbitrary actions within the application environment with the privileges of a legitimate component. The attack requires only network connectivity to the Message Server; no prior authentication or user interaction is required. SAP released patches on 2026-09-08 as part of their Security Patch Day program.

Affected products

  • SAP NetWeaver <unknown>

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory: Published as part of SAP Security Patch Day

References

Related threats