Skip to content

Apache WSS4J: authentication bypass

Critical9.8CVE-2026-88920 · Published Sep 30, 2026 · updated Oct 2, 2026

An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

Affected versions

PackageAffectedFixed in
Apache WSS4J
Product
>= 4.0.0, < 4.0.24.0.2
>= 3.0.0, < 3.0.63.0.6
< 2.4.42.4.4
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache WSS4J: integer overflow
High7.5Sep 30
Apache WSS4J: insufficient authenticity check
Critical9.1Sep 30
Apache WSS4J: protection mechanism failure
High7.5Sep 30
Apache WSS4J: authentication bypass by spoofing
Medium4.8Sep 30
Apache WSS4J: expression injection
Critical9.1Sep 30
Apache WSS4J: resource exhaustion
High7.5Sep 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.