SAP PI SOAP Adapter DoS via Deeply Nested Entity Definitions
CVE-2026-58234 Published on September 8, 2026
Denial of Service vulnerability in SAP Process Integration (SOAP Adapter)
SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with no impact on confidentiality and integrity.
Vulnerability Analysis
CVE-2026-58234 is exploitable with network access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a small impact on availability.
Weakness Type
What is a XEE Vulnerability?
The software uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities. If the DTD contains a large number of nested or recursive entities, this can lead to explosive growth of data when parsed, causing a denial of service.
CVE-2026-58234 has been classified to as a XEE vulnerability or weakness.
Affected Versions
SAP_SE SAP Process Integration (SOAP Adapter):- Version MESSAGING 7.50 is affected.
- Version SAP_XIAF 7.50 is affected.