Security · October 3, 2026
Apache WSS4J patched against seven security flaws including authentication bypass
Apache WSS4J, a library used to apply WS-Security to SOAP messages in Java environments, has been found vulnerable to seven security issues, and an updated version has been released to address them.
The development team disclosed multiple security advisories on September 30, 2026, confirming that all seven vulnerabilities have now been resolved.
Among them, CVE-2026-88920, CVE-2026-89238, and CVE-2026-95616 were rated as Important, the second-highest severity level.
CVE-2026-88920 is an authentication bypass flaw in the DOM security processor. An attacker can include a controlled key in a crafted unsigned sender-vouches SAML assertion to forge an already authenticated SOAP message.
CVE-2026-89238 involves improper handling of encryption headers, allowing an attacker-supplied plaintext element to be treated as a decrypted header, potentially undermining confidentiality and bypassing security policies.