Authentication Bypass Vulnerability in Szafir SDK by Elekroniczny Podpis
CVE-2026-9058
9.3CRITICAL
What is CVE-2026-9058?
The Szafir SDK contains a significant vulnerability where it improperly returns a success status code during the cryptographic digital signature verification process, even when the signer's certificate trust status remains undetermined. This flaw allows applications utilizing Szafir SDK to mistakenly accept invalid digital signatures, leading to potential authentication bypass and unauthorized user impersonation.
Affected Version(s)
Szafir SDK 0 < 463
