SAML Token Validation Flaw in Apache CXF Affects Multiple Versions
CVE-2026-97791
Currently unrated
What is CVE-2026-97791?
In Apache CXF, the STSTokenValidator component fails to adequately segregate validation results across requests. This flaw allows a remote, unauthenticated attacker to exploit the system by sending a maliciously crafted SAML assertion signed with an untrusted certificate. Consequently, the system may erroneously treat the forged assertion as valid without consulting the Security Token Service (STS). This issue primarily impacts services utilizing the STSTokenValidator under certain configuration settings, emphasizing the need for users to update to the latest versions for enhanced security.
Affected Version(s)
Apache CXF 4.2.0 < 4.2.4
Apache CXF 4.0.0 < 4.1.9
Apache CXF 0 < 3.6.13