Skip to content

CVE-2026-58240

SAP NetWeaver Message Server missing authentication check lets unauthenticated attackers register components (CVE-2026-58240)

Critical 9.8 Vendor: SAP Published

SAP NetWeaver Message Server KERNEL 9.16, 9.18, 9.19 and 9.20 lacks an authentication check. An unauthenticated attacker with network access could register an unauthorised component, with high impact on confidentiality, integrity and availability. Apply SAP Note 3759472.

What happened

SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker who can reach the Message Server over the network can register an unauthorised component and then potentially perform unauthorised actions inside the application environment. SAP rates the issue critical, with a CVSS 3.1 score of 9.8, describing network access, low attack complexity, no privileges, no user interaction and high impact on confidentiality, integrity and availability.

The September 2026 SAP advisory does not state that this vulnerability has been exploited in the wild or publicly disclosed, and the CVE record lists no exploitation or public disclosure.

Who is affected

The affected product is SAP NetWeaver (Message Server). Affected versions are KERNEL 9.16, 9.18, 9.19 and 9.20. Organisations running SAP NetWeaver with one of these kernel versions should treat the Message Server as affected, especially if the service is reachable beyond the SAP application servers themselves.

What to do now

  1. Confirm whether your SAP NetWeaver installation runs KERNEL 9.16, 9.18, 9.19 or 9.20.
  2. Apply SAP Note 3759472, the fix SAP has published for CVE-2026-58240. The advisory does not list specific replacement kernel version numbers, so use the note to identify the correct update.
  3. Until the note has been applied, restrict network access to the Message Server so that only trusted SAP application servers and administrative hosts can reach it.
  4. After applying the note, confirm that only authorised application server components can register with the Message Server.

How to detect it

Review Message Server logs for registration events from hosts that are not part of your known SAP landscape. Unexpected registrations from unknown network segments are the activity most directly tied to this weakness. If the Message Server is reachable from segments that do not need access, treat that exposure as a detection priority. The advisory materials do not list vendor-specific indicators of compromise.

Beyond the patch

Beyond applying the note, this is a reminder that an unauthenticated network path to a core SAP component can turn a missing authentication check into a high-impact event. SAP HANA Security & Cloud Migration can help SAP estates work through SAP Note 3759472 and the surrounding kernel update, while Virtual CISO Services (vCISO) can help identify network-exposed SAP services before they are targeted.

Affected and fixed versions

ProductAffectedFixed in
SAP NetWeaver (Message Server)KERNEL 9.16
9.18
9.19
9.20
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.