CVE-2026-58240: pre-auth component registration bypass in SAP SAP NetWeaver (Message Server)

An unauthenticated attacker with network access can register unauthorized internal components on SAP NetWeaver (Message Server), allowing them to perform actions that may compromise confidentiality, integrity, and availability. This issue is tracked as CVE-2026-58240. Affected releases include KERNEL 9.16 and 9.x releases 9.18, 9.19, and 9.20. Exploitation requires only network access to the vulnerable Message Server; no credentials or user interaction are required for an attacker to attempt registration of a rogue component.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00528
CWE
CWE-308
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is a network-accessible, unauthenticated flaw with a high-severity impact (CVSS 9.8), so restrict exposure of Message Server interfaces immediately and prioritize vendor fixes when available.

What is CVE-2026-58240?

An unauthenticated attacker with network access can register unauthorized internal components on SAP NetWeaver (Message Server), allowing them to perform actions that may compromise confidentiality, integrity, and availability. This issue is tracked as CVE-2026-58240. Affected releases include KERNEL 9.16 and 9.x releases 9.18, 9.19, and 9.20. Exploitation requires only network access to the vulnerable Message Server; no credentials or user interaction are required for an attacker to attempt registration of a rogue component.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of SAP SAP NetWeaver (Message Server) are affected?

BRANCHAFFECTEDFIXED
SAP NetWeaver (Message Server)KERNEL 9.16
9.x9.18
9.x9.19
9.x9.20

Is CVE-2026-58240 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-58240

  1. Isolate Message Server endpoints from untrusted networks and limit access to trusted management networks.
  2. Apply network controls (firewalls, ACLs) to block unnecessary inbound access to Message Server ports.
  3. Enable and review logging for component registration and suspicious internal component activity.
  4. Follow SAP security guidance and apply vendor patches or mitigations as soon as they are released.

Frequently asked questions

Is CVE-2026-58240 being actively exploited?

There are no public reports of exploitation of CVE-2026-58240 as of 2026-09-29.

Which SAP NetWeaver (Message Server) versions are affected by CVE-2026-58240?

SAP NetWeaver (Message Server) KERNEL 9.16 and 9.x releases 9.18, 9.19, and 9.20 are listed as affected.

Is there a patch for CVE-2026-58240?

No vendor-fixed versions are listed; a patch is not available based on the provided facts.

Does CVE-2026-58240 require authentication?

No; the vulnerability can be exploited without authentication if an attacker has network access to the Message Server.

References