CVE-2026-89238
Received
Received - Intake
WSS4J Header Confusion Leading to Policy Bypass
Vulnerability report for CVE-2026-89238, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-30
Last updated on: 2026-09-30
Assigner: Apache Software Foundation
Description
Description
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apache | wss4j | 4.0.2 |
| apache | wss4j | 3.0.6 |
| apache | wss4j | 2.4.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |