VORANT. Threat Intelligence Sign in Get the full feed

CVE-2026-9058 in Szafir SDK allows authentication bypass by returning success on…

critical vulnerability

CVE-2026-9058 in Szafir SDK allows authentication bypass by returning success on signature verification even when certificate trust cannot be established, fixed in version 463.

CERT Polska coordinated disclosure of CVE-2026-9058, a critical vulnerability in Szafir SDK software that affects cryptographic signature verification. The flaw causes the SDK to return a success status code during digital signature verification even when the trust status of the signer's certificate cannot be determined. Specifically, the verification process reports a positive result (code 0) while simultaneously marking the certificate type as 'nondetermined', creating a logic error in the trust validation flow.

This vulnerability enables attackers to bypass authentication mechanisms and impersonate legitimate users in applications consuming the SDK's verification results. Applications relying on Szafir SDK would incorrectly accept signatures with unverified certificate chains as valid, undermining the entire purpose of cryptographic signature validation. The issue represents a fundamental failure in the security-critical path of certificate chain validation.

The vulnerability has been remediated in Szafir SDK version 463. The issue was responsibly disclosed by security researcher Michał Leszczyński from icedev.pl. Organizations using affected versions of Szafir SDK should prioritize upgrading to version 463 or later to prevent potential authentication bypass attacks.

Mentioned in this report

Vulnerabilities CVE-2026-9058

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-9058

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free