CVE-2026-88920: Apache WSS4J: SAML Sender-Vouches Authentication Bypass
Apache WSS4J DOM flaw lets attackers forge authenticated SOAP messages via SAML Sender-Vouches (CVE-2026-88920).
Apache disclosed CVE-2026-88920, an important authentication bypass in the DOM security processor of Apache WSS4J. Unauthenticated remote attackers can forge authenticated SOAP messages through a crafted unsigned SAML Sender-Vouches flow. Affected versions are wss4j-ws-security-dom before 2.4.4, 3.0.0 before 3.0.6, and 4.0.0 before 4.0.2. The advisory does not say the flaw is being exploited.
- Important SAML Sender-Vouches authentication bypass in WSS4J DOM.
- Unauthenticated remote attackers can forge authenticated SOAP messages.
- Bypass uses a crafted unsigned SAML-related message.
- Fixes are 2.4.4, 3.0.6, and 4.0.2; no active exploitation stated.
Vulnerabilities mentionedAll →
- CVE-2026-889209.8—SAML Sender-Vouches Authentication Bypass in Apache WSS4Jpublished · Apache WSS4J
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-88920 | SAML Sender-Vouches Authentication Bypass in Apache WSS4J An authentication bypass in the DOM security processor of Apache WSS4J lets unauthenticated remote attackers forge SOAP messages that the service treats as authenticated. The flaw is triggered by a crafted unsigned SAML sender-vouches assertion that contains an attacker-controlled key. An attacker can thereby impersonate a trusted sender and invoke web-service operations that rely on that assertion for authentication. Applications and services that validate WS-Security with a vulnerable Apache WSS4J release are affected; the issue is fixed in 2.4.4, 3.0.6, and 4.0.2. No public proof of concept is known, the CVE is not in the CISA KEV catalog, and CVSS has not yet been scored. Upgrade Apache WSS4J to 4.0.2, 3.0.6, or 2.4.4 and redeploy every application that bundles the library, confirming the version actually loaded at runtime. Until then, limit network exposure of SOAP endpoints that accept SAML sender-vouches assertions and treat those assertions as untrusted. |
Posted by Colm O hEigeartaigh on Sep 30 Severity: important Affected versions: - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-dom) 4.0.0 before 4.0.2 - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-dom) 3.0.0 before 3.0.6 - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-dom) before 2.4.4 Description: An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned...
This source does not provide full text. Read it at seclists.org.