PT-2026-47530 · Sap · Sap Netweaver Application Server Java

CVE-2026-40128

·

Published

2026-06-09

·

Updated

2026-07-14

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server Java (Web Container) (affected versions not specified)
Description An unauthenticated attacker can craft a malicious HTTP logon request that manipulates file inclusion parameters. This enables path traversal, which is a method used to access files and directories that are stored outside the web root folder, and the processing of the included file. This action could allow the attacker to view or modify sensitive information or render any part of the local system unavailable.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08448
CVE-2026-40128

Affected Products

Sap Netweaver Application Server Java