CVE-2026-92899
Published 30 September 2026 · tracked since 1 October 2026
Description
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-96343 HIGH 7.2
- CVE-2026-96344 HIGH 7.2
- CVE-2026-95531 HIGH 8.8
- CVE-2026-94677 HIGH 7.2
- CVE-2026-94678 HIGH 8.8
- CVE-2026-94683 HIGH 8.8
- CVE-2026-94121 HIGH 8.8
- CVE-2026-94122 HIGH 7.2
- CVE-2026-94076 HIGH 8.8
- CVE-2026-94081 HIGH 7.1