Szafir SDK returns a success status code from the cryptographic digital signature verification process (i.e. /VerifyingTaskItem/Signature/VerificationResult/Result/@code == 0, "Positively verified") even when the trust status of the signer's certificate could not be established (i.e. /VerifyingTaskItem/Signature/VerificationResult/SigningCertificate/@certificateType == "nondetermined"). This causes consuming applications to incorrectly treat the signature as valid despite an unverified certificate chain, enabling authentication bypass and user impersonation.
This issue was fixed in version 463.
CVSS
No CVSS.
References
Configurations
No configuration.
History
25 May 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-25 14:16
Updated : 2026-05-26 19:59
NVD link : CVE-2026-9058
Mitre link : CVE-2026-9058
CVE.ORG link : CVE-2026-9058
JSON object : View
Products Affected
No product.
