Szafir SDK returns a success status code from the cryptographic digital signature verification process (i.e. /VerifyingTaskItem/Signature/VerificationResult/Result/@code == 0, "Positively verified") even when the trust status of the signer's certificate could not be established (i.e. /VerifyingTaskItem/Signature/VerificationResult/SigningCertificate/@certificateType == "nondetermined"). This causes consuming applications to incorrectly treat the signature as valid despite an unverified certificate chain, enabling authentication bypass and user impersonation.
This issue was fixed in version 463.
Metrics
Affected Vendors & Products
References
History
Mon, 25 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Szafir SDK returns a success status code from the cryptographic digital signature verification process (i.e. /VerifyingTaskItem/Signature/VerificationResult/Result/@code == 0, "Positively verified") even when the trust status of the signer's certificate could not be established (i.e. /VerifyingTaskItem/Signature/VerificationResult/SigningCertificate/@certificateType == "nondetermined"). This causes consuming applications to incorrectly treat the signature as valid despite an unverified certificate chain, enabling authentication bypass and user impersonation. This issue was fixed in version 463. | |
| Title | Improper Certificate Verification in Szafir SDK | |
| Weaknesses | CWE-393 CWE-637 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-05-25T13:23:09.157Z
Reserved: 2026-05-20T06:36:10.929Z
Link: CVE-2026-9058
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-05-25T14:45:16Z