CVE-2026-88920
EUVD-2026-8979330.09.2026, 12:17
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| apache | wss4j | 4.0.0 ≤ 𝑥 < 4.0.2 | CNA |
| apache | wss4j | 3.0.0 ≤ 𝑥 < 3.0.6 | CNA |
| apache | wss4j | 𝑥 < 2.4.4 | CNA |
Debian Releases
Common Weakness Enumeration