Path Traversal via FileInclusion in SAP NetWeaver App Server Web Container
CVE-2026-40128 Published on June 9, 2026
Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container)
SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable.
Vulnerability Analysis
CVE-2026-40128 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
Path Traversal: '.../...//'
The software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.
Products Associated with CVE-2026-40128
Want to know whenever a new CVE is published for SAP Netweaver Application Server Java? stack.watch will email you.