PT-2026-108867 · Apache · Apache Cxf

·

CVE-2026-97791

·

Published

2026-10-09

·

Updated

2026-10-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Apache CXF versions prior to 4.2.4 Apache CXF versions prior to 4.1.9 Apache CXF versions prior to 3.6.13
Description An issue exists in the STSTokenValidator where the result of the SAML assertion signature check is stored in an object shared across all requests. This allows a remote, unauthenticated attacker to send a forged assertion signed with an untrusted certificate. If legitimate requests are processed simultaneously, the forged assertion may be incorrectly accepted as trusted without being sent to the Security Token Service (STS). This affects services using STSTokenValidator to validate SAML tokens where the alwaysValidateToSts variable is not set.
Recommendations Upgrade to version 4.2.4. Upgrade to version 4.1.9. Upgrade to version 3.6.13.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97791

Affected Products

Apache Cxf