CVE-2026-88920

CVE-2026-88920 published: An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recomm...

View full NVD advisory → ← Back to CVE watch