HarborGuard / CVE
Back to search
CRITICALCVE-2026-9058Published Modified CNA CERT-PL

CVE-2026-9058: Improper Certificate Verification in Szafir SDK

Szafir SDK returns a success status code from the cryptographic digital signature verification process (i.e. /VerifyingTaskItem/Signature/VerificationResult/Result/@code == 0, "Positively verified") even when the trust status of the signer's certificate could not be established (i.e. /VerifyingTaskItem/Signature/VerificationResult/SigningCertificate/@certificateType == "nondetermined"). This causes consuming applications to incorrectly treat the signature as valid despite an unverified certificate chain, enabling authentication bypass and user impersonation. This issue was fixed in version 463.

Metrics

CVSS v4.0
9.3
Severity
CRITICAL
Fixed in
463
Affected Products
1

Fix available

463
Affected packages
  • Krajowa Izba Rozliczeniowa / Szafir SDK
    < 463 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N