PT-2026-103133 · Apache · Wss4J

·

CVE-2026-92121

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions WSS4J versions prior to 4.0.2 WSS4J versions prior to 3.0.6 WSS4J versions prior to 2.4.4
Description In the streaming (StAX) code, a signature reference using the WS-Security STR-Transform causes an internal flag indicating content is signed to remain permanently set. The WS-SecurityPolicy enforcer relies on this flag to determine if an element requires checking; consequently, it ceases evaluating SignedParts and SignedElements for the remainder of the message. This allows a policy requiring the SOAP Body to be signed to be satisfied even if the Body lacks a signature, which eliminates protection against XML Signature Wrapping (a technique where an attacker modifies the XML structure to bypass security checks). Signature verification and DOM code remain unaffected.
Recommendations Upgrade to version 4.0.2. Upgrade to version 3.0.6. Upgrade to version 2.4.4.

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92121

Affected Products

Wss4J