Description
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Published: 2026-09-30
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache wss4j
Vendors & Products Apache
Apache wss4j

Wed, 30 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-285

Wed, 30 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
References

Wed, 30 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Title Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selection
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-30T12:12:23.272Z

Reserved: 2026-09-11T10:07:05.047Z

Link: CVE-2026-89238

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T13:17:21.587

Modified: 2026-09-30T13:17:21.587

Link: CVE-2026-89238

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T14:15:15Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-285

    Improper Authorization