# CVE-2026-58235

## Summary

- **CVE ID:** CVE-2026-58235
- **Severity:** MEDIUM
- **CVSS Score:** 6.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)
- **CWE:** CWE-1395
- **Published:** Aug 11, 2026
- **Last Modified:** Aug 11, 2026

## Description

SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated attacker could potentially leverage these weaknesses against the affected component, though no specific exploit is currently known. Successful exploitation could result in low impact on confidentiality, integrity, and availability of the system.

## Affected Products

- SAP_SE — SAP NetWeaver AS Java (Adobe Document Services) (ADSSAP 7.50)

## References

- [CNA](https://me.sap.com/notes/3758318)
- [CNA](https://url.sap/sapsecuritypatchday)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 7.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._