Path Traversal via FileInclusion in SAP NetWeaver App Server Web Container
CVE-2026-40128 Published on June 9, 2026

Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container)
SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable.

NVD

Vulnerability Analysis

CVE-2026-40128 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

Path Traversal: '.../...//'

The software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.


Products Associated with CVE-2026-40128

Want to know whenever a new CVE is published for SAP Netweaver Application Server Java? stack.watch will email you.

 

Affected Versions

SAP_SE SAP NetWeaver Application Server Java (Web Container) Version ENGINEAPI 7.50 is affected by CVE-2026-40128