OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-89238

CRITICAL · CVSS 9.1 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability in WSS4J allows an attacker to manipulate the decryption process, potentially promoting a malicious plaintext element as the decrypted header, which compromises confidentiality and may lead to policy bypass. Organizations utilizing affected versions of WSS4J should prioritize upgrading to versions 4.0.2, 3.0.6, or 2.4.4 to mitigate this risk. This issue is particularly critical for those handling sensitive data or relying on secure messaging protocols.

CVE
CVE-2026-89238
Severity
CRITICAL
CVSS
9.1
EPSS
0.21%

Original NVD Description

WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.