External risk intelligence

Apache WSS4J Authentication Bypass via SAML Assertion.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-88920

Apache WSS4J is a Java library used for securing SOAP web services. While these services are often exposed to the internet as APIs, WSS4J is a middleware component embedded within applications rather than a standalone edge gateway or internet-facing appliance. Public exposure depends entirely on the specific implementation and architecture of the host application using the library.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects a component within Apache WSS4J, which is used for securing web services. The issue allows unauthenticated remote attackers to bypass security checks and forge authenticated messages. While the direct impact depends on how this component is implemented and exposed within our systems, the potential for unauthorized access to authenticated services is the primary concern.

  • Bypass security to forge authenticated messages.
  • Matters if our systems use this web service security.
  • Confirm relevance and assess exposure to services.

Attack Path

How an attacker could exploit the issue

An attacker can forge authenticated SOAP messages by sending a specially crafted SAML assertion to a system using the vulnerable DOM security processor. This bypasses authentication, allowing unauthorized access and potentially leading to further compromise of the application.

  • No authentication required for attack.
  • Craft SAML assertion to bypass checks.
  • Forge authenticated messages.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, unauthenticated remote attackers could forge authenticated SOAP messages by crafting a SAML assertion with an attacker-controlled key, potentially impacting the integrity and availability of services that rely on WSS4J for authentication.

  • Authenticated SOAP messages could be forged.
  • Attackers could craft specific SAML assertions.
  • Service integrity and availability could be impacted.

Operational Fix

Recommended remediation, mitigation, and detection steps

Apache WSS4J is a Java library, so teams responsible for Java applications and their underlying infrastructure are likely involved. The first step is to inventory where this library is deployed, determine its exposure and criticality, and identify the specific application owners. This will inform a prioritized remediation plan.

  • Application owners must lead remediation efforts.
  • Verify WSS4J instances and their reachability.
  • Plan updates based on identified business risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Apache WSS4J?

Apache WSS4J is a Java library designed to secure web services that communicate via the SOAP protocol. It acts as a middleware component, often embedded inside larger enterprise applications, to handle security tasks like message encryption, signature verification, and authentication. Developers rely on it to ensure that the data exchanged between services remains private and verifiable.

What does CWE-287 mean for CVE-2026-88920?

CWE-287 refers to Improper Authentication. In the context of CVE-2026-88920, this vulnerability exists in the library's DOM security processor. It means the system fails to correctly verify the identity of a sender. An attacker can exploit this weakness by crafting a fake SAML assertion—a digital document used to prove identity—to trick the application into believing an unauthenticated request is legitimate.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a malformed or crafted SAML assertion to a system using the vulnerable library. The attack succeeds because the processor accepts an unsigned assertion containing a key controlled by the attacker. Simply sending valid, properly signed requests or using standard, non-SAML authentication methods does not trigger this specific flaw.

Do I need to worry if my service is internal?

Yes, you should still evaluate the risk. According to Halo Surface Signal, because Apache WSS4J is an embedded middleware component rather than a standalone appliance, its actual accessibility depends on your specific application architecture. While internet-facing services are often at higher risk, any service reachable by an attacker who has gained a foothold on your internal network could potentially be targeted.

When should I start the remediation process?

You should begin by identifying which of your Java applications include the WSS4J library. Once you have a list of affected software, coordinate with the respective application owners to prioritize updates. The primary remediation step is to update the library to version 4.0.2, 3.0.6, or 2.4.4, depending on which release branch your infrastructure currently utilizes.

References