CVE-2026-87830
CVE-2026-87830
9.1
CriticalPublished:
Last updated:
Source:security@apache.org
Analyzed
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- None
Description
In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
References
security@apache.org
https://lists.apache.org/thread.html/lwlozb1x20d16f9dnyvoygc9rrhzq2vnaf854a3a-2127-422b-91ae-364da2661108
http://www.openwall.com/lists/oss-security/2026/09/30/9