CVE-2026-88920

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-30: 109-30
Referenced assets1 URL
By indicator
Full discourse1 post
  • SecAlerts@SecAlertsCo

    🔐 Apache WSS4J (CVSS 9.8): unauthenticated attackers can forge authenticated SOAP messages via crafted unsigned SAML sender-vouches assertions. CVE-2026-88920 hits the DOM security processor. Patch now. #cybersecurity #ciso #cto https://secalerts.co/vulnerability/CVE-2026-88920?utm_campaign=x https://t.co/khwjGd3oG7

    0001178
    893 followersView on X

Explore more