Skip to main content

CVE detail

CVE-2026-40128

SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable.

CVSS 9.0 · CriticalBuzz score 32.6

Buzz score

Why this CVE is surfacing

Buzz score total 32.6

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 16.1 · diversity 16.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
16.1
4 evidence mentions in the snapshot
Diversity score
16.5
4 sources across 3 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
4 source links · newest first
  • June’s Patch Tuesday security updates have arrived, with SAP fixing four critical vulnerabilities and Microsoft addressing over 200 CVEs. Microsoft’s to-do list includes fixes for three zero days, 32 patches rated as ‘critical’, and a batch of other high-risk vulnerabilities that need urgent assessment. There’s also one older flaw under exploit, and some patches affecting […]

    newswww.csoonline.comJun 10, 2026, 2:53 PM
  • The flaws could lead to the disclosure of sensitive information, memory corruption, and disruption of normal system usage.

    newswww.securityweek.comJun 9, 2026, 12:15 PM
  • No excerpt available.

    Vendor Advisoryurl.sapJun 9, 2026, 1:16 AM
  • No excerpt available.

    Permissions Requiredme.sap.comJun 9, 2026, 1:16 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2025-59181

    Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directo…

    CVSS 4.8 · Medium
    1 mention
  • CVE-2025-60835

    An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.

    CVSS 7.8 · High
    4 mentions
  • CVE-2026-49779

    Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal. This issue affects Tax Exempt for WooCommerce: from n/a before 1.9.5.

    CVSS 6.5 · Medium
    2 mentions
  • CVE-2026-52707

    Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.

    CVSS 8.1 · High
    2 mentions
  • CVE-2026-52703

    Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.

    CVSS 9.6 · Critical
    2 mentions
  • CVE-2026-49112

    Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.

    CVSS 7.5 · High
    2 mentions