Description
In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy requiring the SOAP Body to be signed is then satisfied even when the Body carries no signature, removing the protection against XML Signature Wrapping. Signature verification itself is unaffected. The DOM code is not affected. 
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4 which fix this issue.
Published: 2026-09-30
Score: n/a
EPSS: n/a
KEV: No
Impact: Bypassing WS‑SecurityPolicy signature verification, enabling XML Signature Wrapping
Action: Immediate Upgrade
AI Analysis

Impact

In the Apache WSS4J streaming (StAX) code, a signature reference that uses the WS‑Security STR‑Transform leaves an internal "inside signed content" flag permanently set. The policy enforcer checks this flag to decide whether later parts of the message must be validated. When the flag remains set, the enforcer stops evaluating SignedParts and SignedElements for the rest of the message, so a policy that requires the SOAP Body to be signed is satisfied even if the Body contains no signature. Signature verification itself is unchanged, but the policy is incorrectly considered satisfied, allowing an attacker to perform XML Signature Wrapping attacks.

Affected Systems

This flaw applies to the streaming implementation of Apache WSS4J provided by Apache Software Foundation. Versions older than 4.0.2 for the 4.x line, older than 3.0.6 for the 3.x line, and older than 2.4.4 for the 2.x line are affected. The DOM-based implementation is not impacted.

Risk and Exploitability

An attacker can craft a SOAP message that bypasses signature checks by exploiting the permanently set flag, potentially allowing unauthorized data modification or privilege escalation. No CVSS score is supplied, and the EPSS value is unavailable, so the exploit probability is uncertain. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, requiring only network access to the application that processes SOAP messages with WSS4J.

Generated by OpenCVE AI on September 30, 2026 at 13:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache WSS4J to version 4.0.2, 3.0.6, or 2.4.4, which includes the patch.
  • If an upgrade cannot be performed immediately, add an explicit signature check for the SOAP Body in the application code to verify that a signature is present and valid.
  • Avoid or disable the use of WS‑SecurityPolicy settings that rely on the STR‑Transform transformation until the library is updated.

Generated by OpenCVE AI on September 30, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache wss4j
Weaknesses CWE-665
Vendors & Products Apache
Apache wss4j

Wed, 30 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
References

Wed, 30 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy requiring the SOAP Body to be signed is then satisfied even when the Body carries no signature, removing the protection against XML Signature Wrapping. Signature verification itself is unaffected. The DOM code is not affected.  Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4 which fix this issue.
Title Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an STR-Transform reference
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-30T12:12:24.367Z

Reserved: 2026-09-15T16:17:48.810Z

Link: CVE-2026-92121

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T13:17:21.710

Modified: 2026-09-30T13:17:21.710

Link: CVE-2026-92121

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T13:30:17Z

Weaknesses