SAML Token Validation Flaw in Apache CXF Affects Multiple Versions
CVE-2026-97791

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
9 October 2026

What is CVE-2026-97791?

In Apache CXF, the STSTokenValidator component fails to adequately segregate validation results across requests. This flaw allows a remote, unauthenticated attacker to exploit the system by sending a maliciously crafted SAML assertion signed with an untrusted certificate. Consequently, the system may erroneously treat the forged assertion as valid without consulting the Security Token Service (STS). This issue primarily impacts services utilizing the STSTokenValidator under certain configuration settings, emphasizing the need for users to update to the latest versions for enhanced security.

Affected Version(s)

Apache CXF 4.2.0 < 4.2.4

Apache CXF 4.0.0 < 4.1.9

Apache CXF 0 < 3.6.13

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MopMonk-AI
.