Authentication Bypass in Apache WSS4J Affects SOAP Message Processing
CVE-2026-88920

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
30 September 2026

What is CVE-2026-88920?

An authentication bypass vulnerability in the DOM security processor of Apache WSS4J allows remote attackers to forge SOAP messages. This occurs through the manipulation of unsigned SAML sender-vouches assertions, where an attacker can control key elements within these assertions, enabling unauthorized message creation. Users are advised to upgrade to the specified versions to mitigate this security risk.

Affected Version(s)

Apache WSS4J 4.0.0 < 4.0.2

Apache WSS4J 3.0.0 < 3.0.6

Apache WSS4J 0 < 2.4.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reported by n0mi1k
.