CVE-2026-58235: Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)
SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated attacker could potentially leverage these weaknesses against the affected component, though no specific exploit is currently known. Successful exploitation could result in low impact on confidentiality, integrity, and availability of the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58235?
The severity of CVE-2026-58235 is medium with a CVSS score of 6.3.
How do I fix CVE-2026-58235?
To fix CVE-2026-58235, update to the latest version of SAP NetWeaver AS Java that no longer uses the vulnerable libraries.
What types of attacks can CVE-2026-58235 enable?
CVE-2026-58235 could allow a low-privileged authenticated attacker to exploit weaknesses in the outdated libraries.
What components are affected by CVE-2026-58235?
CVE-2026-58235 affects the Adobe Document Services within SAP NetWeaver Application Server Java.
When was CVE-2026-58235 published?
CVE-2026-58235 was published on August 11, 2026.