This issue was fixed in version 463.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Krajowa Izba Rozliczeniowa
Krajowa Izba Rozliczeniowa szafir Sdk |
|
| Vendors & Products |
Krajowa Izba Rozliczeniowa
Krajowa Izba Rozliczeniowa szafir Sdk |
Tue, 26 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Szafir SDK returns a success status code from the cryptographic digital signature verification process (i.e. /VerifyingTaskItem/Signature/VerificationResult/Result/@code == 0, "Positively verified") even when the trust status of the signer's certificate could not be established (i.e. /VerifyingTaskItem/Signature/VerificationResult/SigningCertificate/@certificateType == "nondetermined"). This causes consuming applications to incorrectly treat the signature as valid despite an unverified certificate chain, enabling authentication bypass and user impersonation. This issue was fixed in version 463. | |
| Title | Improper Certificate Verification in Szafir SDK | |
| Weaknesses | CWE-393 CWE-637 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-05-26T15:58:01.602Z
Reserved: 2026-05-20T06:36:10.929Z
Link: CVE-2026-9058
Updated: 2026-05-26T15:57:58.683Z
Status : Deferred
Published: 2026-05-25T14:16:27.977
Modified: 2026-06-17T11:04:47.000
Link: CVE-2026-9058
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:05:59Z