{"api_version":"1","generated_at":"2026-09-30T21:46:49+00:00","cve":"CVE-2026-89238","urls":{"html":"https://cve.report/CVE-2026-89238","api":"https://cve.report/api/cve/CVE-2026-89238.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-89238","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89238"},"summary":{"title":"Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selection","description":"WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.\nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.","state":"PUBLISHED","assigner":"apache","published_at":"2026-09-30 13:17:21","updated_at":"2026-09-30 20:17:35"},"problem_types":["CWE-345","CWE-345 CWE-345 Insufficient Verification of Data Authenticity"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"9.1","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"9.1","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}}],"references":[{"url":"https://lists.apache.org/thread.html/1lv4hpl8kon1ns5txjnhn2m2sh9rl22w","name":"https://lists.apache.org/thread.html/1lv4hpl8kon1ns5txjnhn2m2sh9rl22w","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/30/11","name":"http://www.openwall.com/lists/oss-security/2026/09/30/11","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89238","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89238","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache WSS4J","version":"affected 4.0.0 4.0.2 semver","platforms":[]},{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache WSS4J","version":"affected 3.0.0 3.0.6 semver","platforms":[]},{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache WSS4J","version":"affected 2.4.4 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Reported by n0mi1k","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2026-09-30T12:12:23.272Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/09/30/11"}],"title":"CVE Program Container"},{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"}},{"other":{"content":{"id":"CVE-2026-89238","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-30T19:49:38.121856Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-345","description":"CWE-345 Insufficient Verification of Data Authenticity","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-30T19:50:20.299Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://repo.maven.apache.org/maven2","defaultStatus":"unaffected","packageName":"org.apache.wss4j:wss4j-ws-security-dom","packageURL":"pkg:maven/org.apache.wss4j/wss4j-ws-security-dom","product":"Apache WSS4J","vendor":"Apache Software Foundation","versions":[{"lessThan":"4.0.2","status":"affected","version":"4.0.0","versionType":"semver"},{"lessThan":"3.0.6","status":"affected","version":"3.0.0","versionType":"semver"},{"lessThan":"2.4.4","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Reported by n0mi1k"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.<br>Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue."}],"value":"WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.\nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue."}],"metrics":[{"other":{"content":{"text":"important"},"type":"Textual description of severity"},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"providerMetadata":{"dateUpdated":"2026-09-30T11:59:09.820Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread.html/1lv4hpl8kon1ns5txjnhn2m2sh9rl22w"}],"source":{"discovery":"UNKNOWN"},"title":"Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selection","x_generator":{"engine":"Vulnogram 1.0.3"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2026-89238","datePublished":"2026-09-30T11:59:09.820Z","dateReserved":"2026-09-11T10:07:05.047Z","dateUpdated":"2026-09-30T19:50:20.299Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-30 13:17:21","lastModifiedDate":"2026-09-30 20:17:35","problem_types":["CWE-345","CWE-345 CWE-345 Insufficient Verification of Data Authenticity"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-30T19:49:38.121856Z","id":"CVE-2026-89238","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"89238","Ordinal":"1","Title":"Apache WSS4J: WSS4J EncryptedHeader child confusion causing wron","CVE":"CVE-2026-89238","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"89238","Ordinal":"1","NoteData":"WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.\nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.","Type":"Description","Title":"Apache WSS4J: WSS4J EncryptedHeader child confusion causing wron"}]}}}