Skip to content
Rota Nacional

Cyber ·

CVE-2026-97791: Apache CXF STSTokenValidator may accept untrusted SAML assertions

Security advisory on Apache CXF STSTokenValidator, which shares the SAML signature validation result across requests. Versions from 4.2.0 before 4.2.4, from 4.0.0 before 4.1.9, and before 3.6.13 are listed as affected.

Advisory CVE-2026-97791, published on 9 October 2026 and rated important, describes a problem in the STSTokenValidator component of Apache CXF. The component checks whether a SAML assertion is signed by a trusted certificate before deciding to send it to the STS. According to the available text, this result was stored in an object shared by all requests, so one request could read the result of another. An unauthenticated remote attacker could, through this flaw, send an untrusted assertion. The text received from the feed is truncated, so we do not reproduce further details about the attack vector or the fix.

The listed affected versions are Apache CXF 4.2.0 before 4.2.4, Apache CXF 4.0.0 before 4.1.9, and Apache CXF versions before 3.6.13. Teams using these libraries in federated authentication services should identify the version in use and check the original advisory for the fixed versions and official guidance.

Rota Nacional does not patch third-party libraries or validate SAML assertions in your system. This record is factual information for security teams. If your team uses AI to study the advisory or plan the update, do not paste logs with personal data, credentials, or internal configurations. Rota detects personal data before any model runs, but that does not replace updating the affected component.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free