Description
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Published: 2026-09-30
Score: n/a
EPSS: n/a
KEV: No
Impact: Wrong protected-header selection causing confidentiality downgrade and potential policy bypass
Action: Patch Upgrade
AI Analysis

Impact

Apache WSS4J is susceptible to a child confusion flaw that allows an attacker to subvert the decryption process: a plaintext element supplied by the attacker can be promoted as the decrypted SOAP header. This incorrect header selection undermines confidentiality coverage and may enable a policy bypass, effectively weakening the security guarantees of encrypted messages.

Affected Systems

All versions of Apache WSS4J older than 4.0.2, 3.0.6, or 2.4.4 are affected. The flaw manifests in the handling of EncryptedHeader child elements within the library’s XML security processing.

Risk and Exploitability

The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating limited publicly known exploitation data. Nevertheless, because the flaw operates during SOAP message decryption, remote attackers with network access to services that use WSS4J can supply crafted encrypted messages to trigger the issue. The absence of a CVSS score precludes precise severity ranking, but the potential for confidentiality loss and policy bypass suggests a substantial risk should the vulnerability be exploited.

Generated by OpenCVE AI on September 30, 2026 at 13:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a patch or upgrade Apache WSS4J to v4.0.2, v3.0.6, or v2.4.4 to address the child confusion issue.
  • Verify that all encrypted SOAP headers are processed using the upgraded library to prevent promotion of attacker‑controlled plaintext elements.
  • Review custom header handling and enforce strict validation to guard against future confidentiality downgrade attacks.

Generated by OpenCVE AI on September 30, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-285

Wed, 30 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
References

Wed, 30 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Title Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selection
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-30T12:12:23.272Z

Reserved: 2026-09-11T10:07:05.047Z

Link: CVE-2026-89238

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T13:17:21.587

Modified: 2026-09-30T13:17:21.587

Link: CVE-2026-89238

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T13:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-285

    Improper Authorization