OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-87830

CRITICAL · CVSS 9.1 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The StAX streaming WS-SecurityPolicy validator is vulnerable due to its handling of certain relative or unsupported XPath expressions, which can lead to a mismatch in expected XML element paths. This flaw allows a remote SOAP peer to send required elements without the necessary signature or encryption, potentially compromising the integrity and confidentiality of the data. Organizations utilizing affected versions should prioritize upgrading to versions 4.0.2, 3.0.6, or 2.4.4 to mitigate this security risk.

CVE
CVE-2026-87830
Severity
CRITICAL
CVSS
9.1
EPSS
0.18%

Original NVD Description

In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.