SAPCVE-2026-58234
SAP Process Integration (SOAP Adapter): XML entity expansion
Low2.2CVE-2026-58234 · Published Sep 8, 2026
SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with no impact on confidentiality and integrity.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SAP Process Integration (SOAP Adapter) Product | <= MESSAGING 7.50 | No fix yet |
| <= SAP_XIAF 7.50 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-776
More SAP advisories
All SAP| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | SAP NetWeaver and ABAP Platform: missing authorization | Medium4.3 | No fix yet |
| Sep 8 | SAP NetWeaver Business Client: code execution | High7.8 | No fix yet |
| Sep 8 | SAP Web Dispatcher, Internet: information disclosure | Medium6.5 | No fix yet |
| Sep 8 | SAP Cloud Application Programming Model (CAP): weakly protected credentials | Critical9.4 | No fix yet |
| Sep 8 | SAP Manufacturing Integration and Intelligence: server-side request forgery | Medium6.5 | No fix yet |
| Sep 8 | SAP UI5 does not sufficiently validate the parent frame's origin against the... | Medium4.3 | No fix yet |