CVE-2026-89238

critical

Description

WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

References

https://lists.apache.org/thread.html/1lv4hpl8kon1ns5txjnhn2m2sh9rl22w

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-89794

http://www.openwall.com/lists/oss-security/2026/09/30/11

Details

Source: Mitre, NVD

Published: 2026-09-30

Updated: 2026-09-30

Risk Information

CVSS v2

Base Score: 9.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

Severity: High

CVSS v3

Base Score: 9.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical

EPSS

EPSS: 0.00233