CVE-2026-0510 affects the User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) due to its use of an obsolete cryptographic algorithm for encrypting User Mapping data. This vulnerability has a CVSS score of 3.0 (LOW), indicating that an attacker with high privileges could exploit it under specific conditions, potentially leading to partial disclosure of sensitive information with low impact on confidentiality and no impact on integrity or availability. There is currently no evidence of active exploitation, no known exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in the KEV catalog, though it has garnered 10 community mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SAP SE | NW AS Java UME User Mapping | ENGINEAPI 7.50, SERVERCORE 7.50, UMEADMIN 7.50CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.