CVE-2026-58240
CVE-2026-58240 is a critical-severity vulnerability with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-308.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- EPSS exploit prediction: 1% (43rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-308
- Published:
- Last modified:
Description
SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system.
Frequently asked questions
- What is CVE-2026-58240?
- SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system.
- How severe is CVE-2026-58240?
- CVE-2026-58240 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-58240 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (43rd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-58240?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2026-58240 published?
- CVE-2026-58240 was published on 2026-09-08 and last updated on 2026-09-09.
References
Other CWE-308 vulnerabilities
- CVE-2026-15616 — Critical (CVSS 9.1): Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor…
- CVE-2023-49075 — High (CVSS 8.4): The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition`…
- CVE-2026-67611 — High (CVSS 8.1): OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to…
- CVE-2026-45749 — High (CVSS 8.1): Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST…
- CVE-2025-42959 — High (CVSS 8.1): An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential,…
- CVE-2024-47652 — High (CVSS 8.1): This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in…