- Description
- SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system.
- Source
- cna@sap.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- cna@sap.com
- CWE-308
- Hype score
- Not currently trending
News: SAP Patch Day: OVERPASS CVE-2026-44756 max-severity kernel EPP overflow lets unprivileged actors get admin on SAP via ICM. Onapsis: 10k+ internet-facing. Also S4GET CVE-2026-58240 unauth Message Server RCE. Patch Sep notes now. https://t.co/l1a1JEeOEJ
@snakeyesV1
8 Sept 2026
97 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ #ExploitGrid Daily Threat Digest Top #Vulnerabilities (#CVEs) of the day CVE-2026-44756 CVE-2026-75650 CVE-2026-86296 CVE-2026-18922 CVE-2026-58240 ..🧵👇
@exploitgrid
8 Sept 2026
74 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
SAP scores a described crash 10.0 and a described takeover 9.8, and the whole gap is one scope metric. September patch day: CVE-2026-44756 and CVE-2026-58240. No exploitation reported. https://t.co/5vpeh6itnD
@severitydaily
8 Sept 2026
54 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-58240 SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacke… https://t.co/46T6olyz9m
@CVEnew
8 Sept 2026
1082 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes