{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89238","assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","state":"PUBLISHED","assignerShortName":"apache","dateReserved":"2026-09-11T10:07:05.047Z","datePublished":"2026-09-30T11:59:09.820Z","dateUpdated":"2026-09-30T19:50:20.299Z"},"containers":{"cna":{"providerMetadata":{"orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache","dateUpdated":"2026-09-30T11:59:09.820Z"},"title":"Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selection","source":{"discovery":"UNKNOWN"},"affected":[{"vendor":"Apache Software Foundation","product":"Apache WSS4J","packageURL":"pkg:maven/org.apache.wss4j/wss4j-ws-security-dom","versions":[{"status":"affected","version":"4.0.0","lessThan":"4.0.2","versionType":"semver"},{"status":"affected","version":"3.0.0","lessThan":"3.0.6","versionType":"semver"},{"status":"affected","version":"0","lessThan":"2.4.4","versionType":"semver"}],"defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.wss4j:wss4j-ws-security-dom"}],"descriptions":[{"value":"WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.\nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.","lang":"en","supportingMedia":[{"type":"text/html","base64":false,"value":"WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.<br>Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue."}]}],"references":[{"url":"https://lists.apache.org/thread.html/1lv4hpl8kon1ns5txjnhn2m2sh9rl22w","tags":["vendor-advisory"]}],"metrics":[{"other":{"type":"Textual description of severity","content":{"text":"important"}},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"credits":[{"lang":"en","value":"Reported by n0mi1k","type":"finder"}],"x_generator":{"engine":"Vulnogram 1.0.3"}},"adp":[{"title":"CVE Program Container","references":[{"url":"http://www.openwall.com/lists/oss-security/2026/09/30/11"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2026-09-30T12:12:23.272Z"}},{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-345","lang":"en","description":"CWE-345 Insufficient Verification of Data Authenticity"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":9.1,"attackVector":"NETWORK","baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"NONE","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-09-30T19:49:38.121856Z","id":"CVE-2026-89238","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-30T19:50:20.299Z"}}]}}