SAP NetWeaver Java ADS Use of Outdated Crypto Libs Enables LowPriv Auth Attack
CVE-2026-58235 Published on August 11, 2026

Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)
SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated attacker could potentially leverage these weaknesses against the affected component, though no specific exploit is currently known. Successful exploitation could result in low impact on confidentiality, integrity, and availability of the system.

NVD

Vulnerability Analysis

CVE-2026-58235 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be low. considered to have a small impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
LOW
Availability Impact:
LOW

Weakness Type

CWE-1395

Products Associated with CVE-2026-58235

Want to know whenever a new CVE is published for SAP NetWeaver? stack.watch will email you.

 

Affected Versions

SAP_SE SAP NetWeaver AS Java (Adobe Document Services) Version ADSSAP 7.50 is affected by CVE-2026-58235