CVE-2026-9058CWE-295CWE-393CWE-637

Improper Certificate Verification in Szafir SDK

Critical · published May 25, 2026

CVSS v4.0
9.3
EPSS
0%
Percentile
23.4
In the wild
Unconfirmed
What it is

For untrusted certificates that contain the "Authority Information Access - caIssuers URI" extension, Szafir SDK will automatically download the parent CA certificate from the specified URL and will import it to its trust store as a "nonqualified" certificate. In such a case, Szafir SDK returns a success status code of 0 ("Positively verified") upon successful cryptographic verification and a certificate status of "nonqualified".

For other types of untrusted certificates, Szafir SDK returns a success status code of 0 ("Positively verified") upon successful cryptographic verification and a certificate status of "nondetermined".

This may lead integrating applications to incorrectly treat the digital signature as valid despite an untrusted certificate chain. This flaw enables authentication bypass and user impersonation:

(1) in use-cases other than qualified certificate authentication, or

(2) if the qualified certificate authentication use-case is not correctly implemented by the integrating application.

This issue was fixed in version 1.8.463.2.

The record
Technical detail
CVSS v4.0
9.3 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS
0.00310 · 23.4th percentile
Weaknesses
CWE-295 · Improper Certificate Validation; CWE-393 · Return of Wrong Status Code; CWE-637 · Unnecessary Complexity in Protection Mechanism (Not Using 'Economy of Mechanism')
Published
2026-05-25T13:23Z
EPSS history
Timeline
  • 25 MAY 13:23Z
    Improper Certificate Verification in Szafir SDK
    cvelistv5