Szafir SDK returns a success status code from the cryptographic digital signature verification process (i.e. /VerifyingTaskItem/Signature/VerificationResult/Result/@code == 0, "Positively verified") even when the trust status of the signer's certificate could not be established (i.e. /VerifyingTaskItem/Signature/VerificationResult/SigningCertificate/@certificateType == "nondetermined"). This causes consuming applications to incorrectly treat the signature as valid despite an unverified certificate chain, enabling authentication bypass and user impersonation.
This issue was fixed in version 463.
Metrics
Affected Vendors & Products
References
History
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Krajowa Izba Rozliczeniowa
Krajowa Izba Rozliczeniowa szafir Sdk |
|
| Vendors & Products |
Krajowa Izba Rozliczeniowa
Krajowa Izba Rozliczeniowa szafir Sdk |
Tue, 26 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Szafir SDK returns a success status code from the cryptographic digital signature verification process (i.e. /VerifyingTaskItem/Signature/VerificationResult/Result/@code == 0, "Positively verified") even when the trust status of the signer's certificate could not be established (i.e. /VerifyingTaskItem/Signature/VerificationResult/SigningCertificate/@certificateType == "nondetermined"). This causes consuming applications to incorrectly treat the signature as valid despite an unverified certificate chain, enabling authentication bypass and user impersonation. This issue was fixed in version 463. | |
| Title | Improper Certificate Verification in Szafir SDK | |
| Weaknesses | CWE-393 CWE-637 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published: 2026-05-25T13:23:09.157Z
Updated: 2026-05-26T15:58:01.602Z
Reserved: 2026-05-20T06:36:10.929Z
Link: CVE-2026-9058
Updated: 2026-05-26T15:57:58.683Z
Status : Deferred
Published: 2026-05-25T14:16:27.977
Modified: 2026-05-26T19:59:22.323
Link: CVE-2026-9058
No data.