# CVE-2026-9058 in Szafir SDK allows authentication bypass by returning success on…

Published: 2026-05-25 · Severity: critical
Canonical: https://vorant.io/reports/2d5dbec4-b9ed-45eb-9b3e-3a9c3f0f1333/cve-2026-9058-in-szafir-sdk-allows-authentication-bypass-by-returning-success-on

> CVE-2026-9058 in Szafir SDK allows authentication bypass by returning success on signature verification even when certificate trust cannot be established, fixed in version 463.

CERT Polska coordinated disclosure of CVE-2026-9058, a critical vulnerability in Szafir SDK software that affects cryptographic signature verification. The flaw causes the SDK to return a success status code during digital signature verification even when the trust status of the signer's certificate cannot be determined. Specifically, the verification process reports a positive result (code 0) while simultaneously marking the certificate type as 'nondetermined', creating a logic error in the trust validation flow.

This vulnerability enables attackers to bypass authentication mechanisms and impersonate legitimate users in applications consuming the SDK's verification results. Applications relying on Szafir SDK would incorrectly accept signatures with unverified certificate chains as valid, undermining the entire purpose of cryptographic signature validation. The issue represents a fundamental failure in the security-critical path of certificate chain validation.

The vulnerability has been remediated in Szafir SDK version 463. The issue was responsibly disclosed by security researcher Michał Leszczyński from icedev.pl. Organizations using affected versions of Szafir SDK should prioritize upgrading to version 463 or later to prevent potential authentication bypass attacks.

## Mentioned in this report

- Vulnerabilities: CVE-2026-9058

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-9058

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/2d5dbec4-b9ed-45eb-9b3e-3a9c3f0f1333/cve-2026-9058-in-szafir-sdk-allows-authentication-bypass-by-returning-success-on.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
