CVE-2026-89238

Summary

WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache WSS4J4.0.0 < 4.0.2affected
Apache Software FoundationApache WSS4J3.0.0 < 3.0.6affected
Apache Software FoundationApache WSS4J0 < 2.4.4affected

Weaknesses

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References