Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 4 min 123 bronnen 2 kritiek 11 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-87830

CRITICAL · 9.1 CVSS Gepubliceerd: CWE-917

Beschrijving

In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

References