Description
SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system.
Published: 2026-09-08
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP NetWeaver Message Server fails to authenticate internal application server components during registration, allowing an unauthenticated attacker with network access to register an unauthorized component. This flaw can lead to unauthorized actions within the application environment, potentially compromising confidentiality, integrity, and availability of the system. The weakness is classified under CWE‑308, reflecting the absence of proper authentication checks.

Affected Systems

The vulnerability affects SAP NetWeaver Message Server as documented by SAP for the SAP_SE vendor. Systems running SAP NetWeaver (Message Server) that have not applied SAP note 3759472 or subsequent patch updates are susceptible. Vendors are advised to consult the referenced SAP service notes for affected product versions.

Risk and Exploitability

With a CVSS base score of 9.8, this flaw is considered critical. The EPSS score is currently unavailable, but the lack of authentication gives attackers a direct path to exploit the service by providing malicious component registration data. Based on the description, it is inferred that the attack requires network access to the Message Server, which may involve open or default ports. Although not listed in CISA KEV, the high severity and the fact that the target is an internal service suggest an elevated risk for with open network access or insufficient segmentation.

Generated by OpenCVE AI on September 8, 2026 at 01:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP security patch available in SAP note 3759472 to enforce authentication for component registration.
  • Restrict network access to the SAP NetWeaver Message Server to trusted hosts or internal networks to limit exposure.
  • Configure the Message Server to reject registrations from unknown components by enabling authentication controls in its configuration (as guided by SAP security best practices).

Generated by OpenCVE AI on September 8, 2026 at 01:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system.
Title Missing Authentication check in SAP NetWeaver (Message Server)
Weaknesses CWE-308
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-09-08T00:10:55.418Z

Reserved: 2026-06-29T19:35:04.185Z

Link: CVE-2026-58240

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T01:17:51.080

Modified: 2026-09-08T01:17:51.080

Link: CVE-2026-58240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T01:30:06Z

Weaknesses
  • CWE-308

    Use of Single-factor Authentication