CVE-2026-88920 PUBLISHED

Apache WSS4J: SAML Sender-Vouches Authentication Bypass

Assigner: apache
Reserved: 10.09.2026 Published: 30.09.2026 Updated: 30.09.2026

An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key.

Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

Product Status

Vendor Apache Software Foundation
Product Apache WSS4J
Versions Default: unaffected
  • affected from 4.0.0 to 4.0.2 (excl.)
  • affected from 3.0.0 to 3.0.6 (excl.)
  • affected from 0 to 2.4.4 (excl.)

Credits

  • Reported by n0mi1k finder

References