Skip to content
Rota Nacional

Guides ·

Apache WSS4J flaw bypasses SAML authentication

A notice published on September 30, 2026 reports that a flaw in Apache WSS4J’s DOM processor may let unauthenticated remote attackers forge authenticated SOAP messages. The alert rates the severity as important and lists affected versions.

A security notice published on September 30, 2026 describes CVE-2026-88920 in Apache WSS4J’s DOM security processor. According to the text, unauthenticated remote attackers may forge authenticated SOAP messages using a crafted unsigned message to exploit a SAML Sender-Vouches authentication bypass. The stated severity is important.

The notice lists org.apache.wss4j:wss4j-ws-security-dom versions 4.0.0 before 4.0.2, 3.0.0 before 3.0.6, and versions before 2.4.4 as affected. Check the version actually used by each application and compare it with the stated boundaries before deciding on an update.

To verify the details and official recommendations, consult the original oss-sec mailing-list notice, attributed to Colm O hEigeartaigh, and Apache WSS4J’s security documentation. Confirm version numbers and remediation guidance in the original sources; the available excerpt is an automatic translation and ends midway through the description.

If you use AI to summarize or apply the notice, share only the necessary excerpts and remove credentials, personal data, sensitive configuration, and internal infrastructure details. Validate any technical recommendation against the official notice and your organization’s tests before changing systems.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free