External risk intelligence

Apache WSS4J WS-SecurityPolicy XPath Validation Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-87830

The vulnerability affects the Apache WSS4J library used in SOAP-based web services. While these services are frequently internet-facing, reachability depends entirely on how the library is integrated into the specific application's configuration and deployment. It is not an edge service itself, but a library component.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A flaw in the StAX streaming WS-SecurityPolicy validator could allow an attacker to bypass signature or encryption requirements by sending an XML element that does not match the expected path. This vulnerability, present in the Apache WSS4J library, has been addressed in recent versions.

  • XML validation weakness bypasses security checks.
  • Affects web services security, a common integration point.
  • Confirm if WSS4J is used and assess exposure.

Attack Path

How an attacker could exploit the issue

A remote attacker could send specially crafted XML to a SOAP service that uses the Apache WSS4J library. The service's security validation component might misinterpret certain XPath expressions, allowing the attacker to bypass signature or encryption requirements for a required element. This could lead to the processing of a malicious or untrusted message.

  • No special access needed.
  • Malicious XML bypasses security checks.
  • Leads to processing untrusted data.

Live Threat

Current exploitation, exposure, and threat context

When a remote SOAP peer sends an XML element without the expected signature or encryption, certain relative or unsupported XPath expressions used by the StAX streaming WS-SecurityPolicy validator could be converted into paths that do not match the actual XML element path, potentially affecting data integrity.

  • Unsigned or unencrypted XML data may be accepted.
  • Malicious SOAP messages could bypass validation.
  • Sensitive information or service integrity could be compromised.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the StAX streaming WS-SecurityPolicy validator impacts systems processing XML with specific XPath expressions, potentially allowing remote attackers to bypass signature or encryption requirements. Owners of applications utilizing the affected Apache WSS4J library must identify all instances of this technology, assess their exposure, and coordinate remediation efforts. The first practical step is to confirm the presence and reachability of the affected technology, identify the accountable owner, and then plan remediation based on the assessed risk.

  • Application or Platform Owners
  • Verify XPath expression handling and XML processing.
  • Plan and execute staged remediation by risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Apache WSS4J?

Apache WSS4J is a Java library widely used to implement Web Services Security standards. It provides functions to secure SOAP messages, such as digital signatures, encryption, and timestamp verification, ensuring that data exchanged between applications remains confidential and authentic.

What does CWE-917 mean for CVE-2026-87830?

CWE-917 is the weakness class for Improper Neutralization of Special Elements used in an Expression Language. In this CVE, the validator incorrectly interprets specific XPath expressions used to locate XML security headers. Because the path is miscalculated, the software fails to enforce security policies, allowing unsigned or unencrypted data to pass through as if it were valid.

How does an attacker trigger this bypass?

An attacker triggers this by sending a specially crafted SOAP message containing unexpected XPath expressions. The vulnerability occurs when these expressions are converted into invalid paths that fail to match actual XML elements. Critically, simply sending valid, properly signed, or standard SOAP traffic that does not rely on these specific problematic XPath lookups does not trigger the bug.

Is my service at risk?

According to Halo Surface Signal, risk depends on how your application integrates WSS4J. While SOAP services are often internet-facing, this library is a component, not an edge service. You are most concerned if your specific application uses the StAX streaming validator to process incoming SOAP messages from untrusted external peers, as this creates a reachable attack path.

When should I update my WSS4J implementation?

You should prioritize updating as soon as you confirm your application includes the affected WSS4J library versions. The first step is to locate where this technology exists in your environment and identify the owners. Once confirmed, plan to upgrade to versions 4.0.2, 3.0.6, or 2.4.4, which contain the necessary fixes for this validation flaw.

References