important · Edge devices
Public SAPMAP code now automates S4GET's pre-authentication takeover path across SAP application-server clusters.
Affects
SAP NetWeaver Message Server and Gateway infrastructure used by SAP S/4HANA, S/4HANA Cloud Private Edition, ABAP Platform, and other ABAP-based systems on affected kernel lines.
From Message Server port 36NN, a crafted registration makes the attacker's IP trusted across the cluster; SAP Gateway then accepts external-program invocation from that address and executes as the SAP operating-system account. A patch is available.
Detail and 3 sources
Sources
ResearchSAPMAP Toolkit Elevates Risks for SAP Customers - OnapsisVendorS4GET (CVE-2026-58240): A Critical Pre-Authentication Vulnerability in SAP NetWeaver's Message ServerVendorOnapsis Research Labs Threat Advisory: Unpacking the SAPMAP Exploitation Toolkit with Latest Threat Insights and Protection Guidance - Onapsis