CVE WATCH / VULNERABILITY DETAIL
CVE-2026-88920
CRITICALCVSS 9.8NVD feed
Published 30 September 2026 · tracked since 1 October 2026
Description
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key.Users are recommended to upgrade to versions 4.0.2 or 3.0.6
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-96343 HIGH 7.2
- CVE-2026-96344 HIGH 7.2
- CVE-2026-95531 HIGH 8.8
- CVE-2026-94677 HIGH 7.2
- CVE-2026-94678 HIGH 8.8
- CVE-2026-94683 HIGH 8.8
- CVE-2026-94121 HIGH 8.8
- CVE-2026-94122 HIGH 7.2
- CVE-2026-94076 HIGH 8.8
- CVE-2026-94081 HIGH 7.1