CVE-2026-88920: Apache WSS4J: SAML Sender-Vouches Authentication Bypass
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache WSS4Jto a version that resolves this vulnerability.Fixed in 4.0.2 - Upgrade
Upgrade
Apache WSS4Jto a version that resolves this vulnerability.Fixed in 3.0.6 - Upgrade
Upgrade
Apache WSS4Jto a version that resolves this vulnerability.Fixed in 2.4.4
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using the DOM security processor in Apache WSS4J are affected when they process SAML sender-vouches assertions. The described attack uses an unsigned sender-vouches assertion with an attacker-controlled key.
Does an attacker need valid credentials to exploit it?
No. The issue allows unauthenticated remote attackers to forge messages that are treated as authenticated.
What versions should be used to remediate the issue?
Upgrade Apache WSS4J to version 4.0.2, 3.0.6, or 2.4.4, as applicable. These versions fix the issue.