Critical SAP NetWeaver Flaw CVE-2026-58240 Allows Unauthenticated Cluster-Wide RCE
A critical vulnerability tracked as CVE-2026-58240, dubbed S4GET, has been disclosed by Onapsis on September 8, 2026, affecting SAP NetWeaver Message Server. The flaw allows an unauthenticated attacker to manipulate the Message Server into treating their IP address as a trusted cluster host, subsequently enabling OS command execution via SAP Gateway with administrator-level privileges. Commands run as the 'adm' OS user across all application servers in the cluster, potentially enabling credential theft, backdoor installation, and lateral movement. SAP has issued Security Note 3759472 with patches across multiple kernel branches, and administrators are urged to restrict SAP GUI connection sources and remove direct internet exposure of the Message Server port. No real-world exploitation has been publicly reported, but the attack requires no user interaction and poses severe risk to any reachable SAP deployment.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in