---
id: CVE-2026-89238
title: >-
  WSS4J EncryptedHeader child confusion could promote an attacker-controlled
  plaintext element as the decrypted header, leading to incorrect
  confidentiality coverage and possible policy bypass.

  Users are recommended to upgrade to versions …
summary: >-
  WSS4J EncryptedHeader child confusion could promote an attacker-controlled
  plaintext element as the decrypted header, leading to incorrect
  confidentiality coverage and possible policy bypass.

  Users are recommended to upgrade to versions …
severity: none
vendor: Apache Software Foundation
product: 'org.apache.wss4j:wss4j-ws-security-dom'
affected:
  - 'org.apache.wss4j:wss4j-ws-security-dom >= 4.0.0 < 4.0.2'
  - 'org.apache.wss4j:wss4j-ws-security-dom >= 3.0.0 < 3.0.6'
  - 'org.apache.wss4j:wss4j-ws-security-dom < 2.4.4'
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T13:17:21.587'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89238'
references:
  - url: 'https://lists.apache.org/thread.html/1lv4hpl8kon1ns5txjnhn2m2sh9rl22w'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/30/11'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T13:03:52.020Z'
---

## Overview

WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
