Description
Improper Verification of Cryptographic Signature vulnerability in Apache CXF's JAX-RS XML Security module. The JAX-RS XML Signature interceptors (XmlSigInHandler, XmlSigInInterceptor and the streaming XmlSecInInterceptor) did not ensure that the XML passed to the application was covered by the signature. An attacker with any document signed by a trusted key could wrap it in unsigned content, which the application would then treat as signed.
Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Privilege Escalation (Unauthorized Execution)
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises because the Apache CXF JAX‑RS XML Security interceptors do not confirm that all XML fragments delivered to the application are covered by a cryptographic signature. An attacker who can supply a document signed with a trusted private key may embed malicious content before or after the signed portion, effectively wrapping the unsigned payload. The application then processes the wrapped content as if it were fully authenticated, potentially allowing unauthorized data manipulation, configuration changes, or execution of tampered code, representing a privilege‑escalation or integrity‑compromise risk.

Affected Systems

The issue affects releases of Apache CXF that contain the JAX‑RS XML Security module prior to the fixes. Vendors affected include the Apache Software Foundation's Apache CXF. Versions older than 4.2.4, 4.1.9 or 3.6.13 are vulnerable; upgrading to these releases or later eliminates the flaw. The vulnerability does not apply to product variants beyond the base JAX‑RS XML Security component.

Risk and Exploitability

The flaw does not require local code execution or special privileges to exploit; it only requires access to a signed XML document from a trusted key. Because the signed part can be freely chosen, an attacker can craft a document that includes arbitrary unsigned elements. The lack of an EPSS or CVSS metric in the data means the ease of exploitation is not quantified, but the threat is present for any deployment that accepts signed XML without integrity checks. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation at the time of data publication.

Generated by OpenCVE AI on October 9, 2026 at 11:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to Apache CXF 4.2.4, 4.1.9, 3.6.13, or newer releases that include the XML Signature fix.
  • Verify that the application's XML security configuration validates the signature against the entire document; disable any custom logic that bypasses this check.
  • If an immediate upgrade is not feasible, enforce strict input validation on incoming XML to reject any signed documents that contain unsigned elements, or temporarily disable the XML Signature interceptors until a patch is applied.

Generated by OpenCVE AI on October 9, 2026 at 11:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-605

Fri, 09 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Description Improper Verification of Cryptographic Signature vulnerability in Apache CXF's JAX-RS XML Security module. The JAX-RS XML Signature interceptors (XmlSigInHandler, XmlSigInInterceptor and the streaming XmlSecInInterceptor) did not ensure that the XML passed to the application was covered by the signature. An attacker with any document signed by a trusted key could wrap it in unsigned content, which the application would then treat as signed. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
Title Apache CXF: XML Signature wrapping in JAX-RS XML Security
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-09T11:07:51.197Z

Reserved: 2026-09-25T15:15:43.370Z

Link: CVE-2026-100227

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T11:17:01.993

Modified: 2026-10-09T11:17:01.993

Link: CVE-2026-100227

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T11:30:06Z

Weaknesses
  • CWE-605

    Multiple Binds to the Same Port