cbcvebase.
CVE-2026-89238
published 2026-09-30

CVE-2026-89238: WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality…

PriorityP354critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.21%
10.8th percentile
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

Affected

6 ranges
VendorProductVersion rangeFixed in
apachewss4j< 2.4.42.4.4
apachewss4j>= 3.0.0 < 3.0.63.0.6
apachewss4j>= 4.0.0 < 4.0.24.0.2
apache_software_foundationapache_wss4j< 2.4.42.4.4
apache_software_foundationapache_wss4j>= 3.0.0 < 3.0.63.0.6
apache_software_foundationapache_wss4j>= 4.0.0 < 4.0.24.0.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.