Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-40128 -- CVSS 9.0 Vulnerability Briefing

CVE-2026-40128 | CVSS 9.0 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-40128 is a path traversal vulnerability in the Web Container component of SAP NetWeaver Application Server Java, exploitable by unauthenticated remote attackers via crafted HTTP logon requests.

Technical Detail

The flaw exists in how the SAP NetWeaver AS Java Web Container processes file inclusion parameters during HTTP logon handling. An unauthenticated attacker can manipulate these parameters to perform path traversal, potentially reading arbitrary files outside the intended directory scope or influencing server-side file inclusion logic. Depending on the server configuration and what files are accessible, successful exploitation could lead to sensitive information disclosure, credential exposure, or further exploitation of the application layer. The CVSS score of 9.0 reflects the low attack complexity and absence of any authentication requirement.

Exploitation Status

No known exploit code has been publicly observed or confirmed as of June 16, 2026. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. No proof-of-concept or operational exploit has been reported at this time, though the unauthenticated attack surface and high severity score make this a candidate for rapid weaponization once technical details circulate.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor associations have been established for this CVE. SAP NetWeaver environments are historically targeted by financially motivated actors and state-sponsored groups, but no such activity has been linked to this specific vulnerability.

What To Do

Apply the relevant SAP Security Note addressing CVE-2026-40128 as a priority, given the critical CVSS score and unauthenticated attack vector. Organizations running SAP NetWeaver AS Java should check the SAP Support Portal for the applicable patch and apply it promptly. As an interim measure, restrict external access to the SAP NetWeaver AS Java logon endpoints at the network perimeter and review web application firewall rules to detect or block requests containing path traversal sequences such as "../" in HTTP parameters. Monitor SAP system logs for anomalous logon requests with unusual file path strings in parameter values. Given the nature of the flaw, prioritize exposure review for any internet-facing SAP NetWeaver AS Java instances.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →