Apache Software FoundationCVE-2026-89238
Apache WSS4J: insufficient authenticity check
Critical9.1CVE-2026-89238 · Published Sep 30, 2026
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache WSS4J Product | >= 4.0.0, < 4.0.2 | 4.0.2 |
| >= 3.0.0, < 3.0.6 | 3.0.6 | |
| < 2.4.4 | 2.4.4 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-345
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 30 | Apache WSS4J: integer overflow | High7.5 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: protection mechanism failure | High7.5 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: authentication bypass by spoofing | Medium4.8 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: expression injection | Critical9.1 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: authentication bypass | Critical9.8 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: resource exhaustion | High7.5 | 4.0.2+2 more |