VORANT. Threat Intelligence Sign in Get the full feed

Szafir SDK flaw enables signature spoofing

medium vulnerability

A vulnerability in Szafir SDK lets untrusted certificates be treated as valid, enabling authentication bypass and impersonation, now fixed in version 1.8.463.2.

CERT Polska coordinated disclosure of CVE-2026-9058, a flaw in Szafir SDK affecting how the library handles certificate validation. When presented with untrusted certificates containing the Authority Information Access caIssuers URI extension, the SDK automatically fetches the parent CA certificate and imports it into its trust store as nonqualified, then reports a success status (0, Positively verified) rather than rejecting the chain. Other untrusted certificate types similarly return a positive verification status with a nondetermined certificate status.

The practical impact is that applications integrating Szafir SDK may incorrectly treat digital signatures as valid despite an untrusted certificate chain, enabling authentication bypass and user impersonation. This is particularly relevant for use-cases outside qualified certificate authentication, or where qualified certificate authentication is not correctly implemented by the integrating application. The vendor has fixed the issue in version 1.8.463.2. The vulnerability was responsibly reported by researcher Michał Leszczyński (icedev.pl), and no evidence of active exploitation is mentioned in the disclosure.

Mentioned in this report

Vulnerabilities CVE-2026-9058

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-9058

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free