0.0
NA
CVE-2026-92899
Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce
Description

Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

INFO

Published Date :

Sept. 30, 2026, 12:02 p.m.

Last Modified :

Sept. 30, 2026, 12:12 p.m.

Remotely Exploit :

No

Source :

apache
Affected Products

The following products are affected by CVE-2026-92899 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Apache wss4j
Solution
Upgrade Apache WSS4J to a patched version to fix replay attacks.
  • Upgrade to Apache WSS4J version 4.0.2.
  • Upgrade to Apache WSS4J version 3.0.6.
  • Upgrade to Apache WSS4J version 2.4.4.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-92899 vulnerability anywhere in the article.

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.