CVE-2026-87830
Received Received - Intake

StAX WS-SecurityPolicy XPath Validation Bypass

Vulnerability report for CVE-2026-87830, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Apache Software Foundation

Description

In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
apache stax_streaming_ws-securitypolicy_validator 4.0.2
apache stax_streaming_ws-securitypolicy_validator 3.0.6
apache stax_streaming_ws-securitypolicy_validator 2.4.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the StAX streaming WS-SecurityPolicy validator incorrectly handling certain XPath expressions. It allows a remote SOAP peer to send a required XML element without proper signature or encryption by exploiting path mismatches in validation.

Detection Guidance

This vulnerability involves improper handling of XPath expressions in WS-SecurityPolicy validation. Detection requires checking for SOAP messages with relative or unsupported XPath expressions that bypass signature or encryption requirements. Inspect XML/SOAP traffic for malformed or unexpected XPath usage in WS-SecurityPolicy headers.

Impact Analysis

An attacker could bypass security checks by sending unsigned or unencrypted data in SOAP messages, potentially leading to unauthorized access or data tampering. Systems relying on WS-SecurityPolicy for message integrity may be compromised.

Compliance Impact

This vulnerability may violate compliance requirements that mandate encryption or signing of sensitive data, such as GDPR's data integrity principles or HIPAA's security rules for protected health information.

Mitigation Strategies

Upgrade to Apache StAX streaming WS-SecurityPolicy validator versions 4.0.2, 3.0.6, or 2.4.4 to fix the issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87830. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart