---
id: CVE-2026-58234
title: >-
  SAP Process Integration (SOAP Adapter) allows a privileged user to send
  specially crafted requests containing deeply nested entity definitions, which
  under certain conditions could temporarily increase processor load and degrade
  system r…
summary: >-
  SAP Process Integration (SOAP Adapter) allows a privileged user to send
  specially crafted requests containing deeply nested entity definitions, which
  under certain conditions could temporarily increase processor load and degrade
  system r…
severity: low
cvss: 2.2
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-776
vendor: SAP_SE
product: SAP Process Integration (SOAP Adapter)
affected:
  - sap_process_integration_soap_adapter MESSAGING 7.50
  - sap_process_integration_soap_adapter SAP_XIAF 7.50
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:12:59.557'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-58234'
references:
  - url: 'https://me.sap.com/notes/3736494'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
  - cve.org
epss: 0.00338
epssPercentile: 0.24531
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T10:05:22.547601Z'
ingestedAt: '2026-09-08T15:33:26.981Z'
---

## Overview

SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with no impact on confidentiality and integrity.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
