Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 |
Wed, 30 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 30 Sep 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. | |
| Title | Apache WSS4J: SAML Sender-Vouches Authentication Bypass | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-09-30T12:12:22.214Z
Reserved: 2026-09-10T13:32:10.370Z
Link: CVE-2026-88920
No data.
Status : Received
Published: 2026-09-30T12:17:14.203
Modified: 2026-09-30T13:17:21.483
Link: CVE-2026-88920
No data.
OpenCVE Enrichment
Updated: 2026-09-30T13:30:17Z
-
CWE-287
Improper Authentication