Junglewise Threat Intelligence

CVE-2026-58235: SAP NetWeaver Application Server Java outdated cryptographic library

CVE-2026-58235 · Severity: medium · CVSS 6.3 · Published 2026-08-11

Technologies: SAP Netweaver Application Server Java. Vendors: SAP.

Executive brief

SAP NetWeaver Application Server Java includes an Adobe Document Service component that relies on outdated open source libraries for cryptography and data transfer. These libraries contain known security weaknesses that have been fixed in newer versions. An authenticated user with low privileges could potentially exploit these weaknesses, though no active exploits are currently known; successful exploitation could compromise the confidentiality, integrity, or availability of the system.

Technical details

This vulnerability stems from the use of outdated open source cryptographic and data transfer libraries within the Adobe Document Service component of SAP NetWeaver Application Server Java. The exact vulnerable libraries and specific weaknesses are not detailed in the advisory, but the root cause is known to involve unpatched dependencies. The attack requires low-privileged authentication to the affected system. An attacker with valid credentials could potentially leverage known vulnerabilities in these libraries to compromise system security. SAP has released security notes and patch day updates to address this issue; customers are advised to apply updates and upgrade affected libraries to patched versions.

Affected products

  • SAP NetWeaver Application Server Java <UNKNOWN>

Timeline

  • 2026-08-11: disclosed
  • other: SAP Security Patch Day scheduled for 2026-08-11

References

Related threats