{"id":"CVE-2026-89238","title":"WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.\nUsers are recommended to upgrade to versions …","summary":"WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.\nUsers are recommended to upgrade to versions …","severity":"none","vendor":"Apache Software Foundation","product":"org.apache.wss4j:wss4j-ws-security-dom","affected":["org.apache.wss4j:wss4j-ws-security-dom >= 4.0.0 < 4.0.2","org.apache.wss4j:wss4j-ws-security-dom >= 3.0.0 < 3.0.6","org.apache.wss4j:wss4j-ws-security-dom < 2.4.4"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T13:17:21.587","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89238","references":[{"url":"https://lists.apache.org/thread.html/1lv4hpl8kon1ns5txjnhn2m2sh9rl22w","label":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/30/11","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T13:03:52.020Z","slug":"CVE-2026-89238","body":"## Overview\n\nWSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.\nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}