Authentication Bypass in Apache WSS4J Affects SOAP Message Processing
CVE-2026-88920
Currently unrated
What is CVE-2026-88920?
An authentication bypass vulnerability in the DOM security processor of Apache WSS4J allows remote attackers to forge SOAP messages. This occurs through the manipulation of unsigned SAML sender-vouches assertions, where an attacker can control key elements within these assertions, enabling unauthorized message creation. Users are advised to upgrade to the specified versions to mitigate this security risk.
Affected Version(s)
Apache WSS4J 4.0.0 < 4.0.2
Apache WSS4J 3.0.0 < 3.0.6
Apache WSS4J 0 < 2.4.4