ZeroHour

CVE-2026-58234

large

Privileged XML Entity Expansion DoS in SAP Process Integration SOAP Adapter

CVSS 3.1
2.2 low
EPSS
<1%p11
Published
()
Modified
AI analysis

CVE-2026-58234 is a low-severity denial-of-service flaw in the SOAP Adapter of SAP Process Integration, caused by improper handling of recursive XML entity definitions (CWE-776). An attacker who already holds highly privileged credentials must send specially crafted SOAP requests containing deeply nested entity definitions, which under certain conditions can drive up processor load. The only impact is a temporary, low-severity degradation of system responsiveness; confidentiality and integrity are unaffected, so the attacker gains at most a brief availability impact rather than code execution or data access. Only organizations running SAP Process Integration with the SOAP Adapter enabled are affected, and only via a highly privileged account (legitimate or compromised). No public proof of concept is known, it is not in CISA's KEV catalog, and EPSS puts the 30-day exploitation probability at just 0.2%; the fix shipped in SAP's September 2026 security updates.

What to do: Apply the SAP Process Integration fix distributed in the September 2026 SAP Security Patch Day, checking the SAP security note for the exact patched versions rather than assuming current patch levels. Because exploitation requires highly privileged access, restrict and audit which accounts may call the SOAP Adapter and rotate or monitor privileged credentials. Monitor processor load and system responsiveness for anomalies as an interim detection measure.

Affected
SAP Process Integration (SOAP Adapter)
Estimated exposure
large≈ tens of thousands of enterprise installations worldwide (exact counts unpublished) — SAP Process Integration/Process Orchestration is a widely deployed integration middleware component in large enterprise SAP landscapes, supporting an order-of-magnitude estimate in the tens of thousands of systems, though no public install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with no impact on confidentiality and integrity.

Weakness
CWE-776
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L

In the news

SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport

SAP's September 2026 Patch Day fixes 19 notes including CVE-2026-44756 (CVSS 10.0), unauthenticated memory corruption in SAP Extended Passport Processing kernels.

SAP shipped 19 new security notes plus one update across NetWeaver, S/4HANA, Integration Suite, Commerce Cloud, and Cloud Application Programming Model. Top issues include CVE-2026-44756 (CVSS 10.0 memory corruption in SAP Extended Passport Processing across many KERNEL and Web Dispatcher versions), CVE-2026-58240 (CVSS 9.8 missing authentication in NetWeaver Message Server), CVE-2026-76969 (CVSS 9.4 credential disclosure in CAP library sap/cds-mtxs), and CVE-2026-66768 (CVSS 9.0 access control flaw in SAP GUI for Java). No exploitation is reported; organizations running affected kernels are urged to patch urgently.