CVE-2026-92899
CVE-2026-92899 is a medium-severity vulnerability in Apache Wss4j with a CVSS 3.x base score of 4.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-290.
Key facts
- Severity: Medium (CVSS 3.x base score 4.8)
- EPSS exploit prediction: 1% (41st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-290
- Affected product: Apache Wss4j
- Published:
- Last modified:
Description
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Frequently asked questions
- What is CVE-2026-92899?
- Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
- How severe is CVE-2026-92899?
- CVE-2026-92899 has a CVSS 3.x base score of 4.8, rated medium severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability none.
- Is CVE-2026-92899 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (41st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-92899?
- CVE-2026-92899 affects Apache Wss4j. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-92899?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-92899 published?
- CVE-2026-92899 was published on 2026-09-30 and last updated on 2026-10-02.
References
- https://lists.apache.org/thread.html/nrzngsz1xm2lztq3t873663xx9wnrwm7
- http://www.openwall.com/lists/oss-security/2026/09/30/13
Affected products (1)
- cpe:2.3:a:apache:wss4j:*:*:*:*:*:*:*:*
More vulnerabilities in Apache Wss4j
- CVE-2026-88920 — Critical (CVSS 9.8): An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge…
- CVE-2026-89238 — Critical (CVSS 9.1): WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header,…
- CVE-2026-87830 — Critical (CVSS 9.1): In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted…
- CVE-2020-13936 — High (CVSS 8.8): An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands…
- CVE-2026-95616 — High (CVSS 7.5): An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated…
- CVE-2026-92121 — High (CVSS 7.5): In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal…
All CVEs affecting Apache Wss4j →
Other CWE-290 vulnerabilities
- CVE-2026-69843 — Critical (CVSS 10.0): Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a…
- CVE-2026-76423 — Critical (CVSS 10.0): A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain…
- CVE-2026-54782 — Critical (CVSS 10.0): CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,…
- CVE-2026-48567 — Critical (CVSS 10.0): Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a…
- CVE-2026-6213 — Critical (CVSS 10.0): A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check…
- CVE-2026-39858 — Critical (CVSS 10.0): Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high…