SAP PI SOAP Adapter DoS via Deeply Nested Entity Definitions
CVE-2026-58234 Published on September 8, 2026

Denial of Service vulnerability in SAP Process Integration (SOAP Adapter)
SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with no impact on confidentiality and integrity.

NVD

Vulnerability Analysis

CVE-2026-58234 is exploitable with network access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a small impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
HIGH
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
NONE
Availability Impact:
LOW

Weakness Type

What is a XEE Vulnerability?

The software uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities. If the DTD contains a large number of nested or recursive entities, this can lead to explosive growth of data when parsed, causing a denial of service.

CVE-2026-58234 has been classified to as a XEE vulnerability or weakness.


Affected Versions

SAP_SE SAP Process Integration (SOAP Adapter):