CVE-2026-88920
published 2026-09-30CVE-2026-88920: An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a…
PriorityP270critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.57%
45.4th percentile
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | wss4j | < 2.4.4 | 2.4.4 |
| apache | wss4j | >= 3.0.0 < 3.0.6 | 3.0.6 |
| apache | wss4j | >= 4.0.0 < 4.0.2 | 4.0.2 |
| apache_software_foundation | apache_wss4j | < 2.4.4 | 2.4.4 |
| apache_software_foundation | apache_wss4j | >= 3.0.0 < 3.0.6 | 3.0.6 |
| apache_software_foundation | apache_wss4j | >= 4.0.0 < 4.0.2 | 4.0.2 |
| jboss-eap-7 | eap74-els-openjdk11-openshift-rhel8 | — | — |
| jboss-eap-7 | eap74-els-openjdk17-openshift-rhel8 | — | — |
| jboss-eap-7 | eap74-els-openjdk8-openshift-rhel8 | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.apache.wss4j/wss4j-ws-security-dom: Apache WSS4J: Authentication bypass via unsigned SAML sender-vouches assertion
vendor_redhat·2026-09-30·CVSS 9.8
CVE-2026-88920 [CRITICAL] CWE-347 org.apache.wss4j/wss4j-ws-security-dom: Apache WSS4J: Authentication bypass via unsigned SAML sender-vouches assertion
org.apache.wss4j/wss4j-ws-security-dom: Apache WSS4J: Authentication bypass via unsigned SAML sender-vouches assertion
A flaw was found in Apache WSS4J. This vulnerability in the Document Object Model (DOM) security processor allows an unauthenticated remote attacker to bypass authentication and forge authenticated Simple Object Access Protocol (SOAP) messages. An attacker can exploit this issue by submitting a crafted, unsigned Security Assertion Markup Language (SAML) sender-vouches assertion containing an attacker-controlled key.
Package: wss4j-ws-security-dom (Red Hat build of Apache Camel 4 for Quarkus 3) - Affected
Package: wss4j-ws-security-dom (Red Hat build of Apache Camel for Spring Boot 4) - Affected
Package: wss4j-ws-security-dom (Red Hat Fuse 7) - Affected
Package: jboss-
GHSA
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion
ghsa_unreviewed·2026-09-30
CVE-2026-88920 An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
No detection rules found.
No public exploits indexed.
2026-09-30
Published