VORANT. Threat Intelligence Sign in Get the full feed

Szafir SDK signature bypass patched in v463

high vulnerability

CVE-2026-9058 in Szafir SDK allowed authentication bypass by returning success for signatures with unverified certificate chains; fixed in version 463.

CERT Polska has disclosed CVE-2026-9058, a vulnerability in Szafir SDK software that enables authentication bypass through improper signature verification. The flaw causes the SDK to return a success status code during digital signature verification even when the trust status of the signer's certificate cannot be established. Applications consuming the SDK's verification results would incorrectly treat signatures as valid despite unverified certificate chains, allowing attackers to bypass authentication controls and potentially impersonate legitimate users.

The vulnerability was responsibly disclosed by Michał Leszczyński of icedev.pl and has been addressed in Szafir SDK version 463. Organizations using earlier versions should upgrade immediately to prevent exploitation. The issue represents a critical failure in the cryptographic verification chain that could undermine the integrity of any authentication or signing workflows dependent on the affected SDK.

Mentioned in this report

Vulnerabilities CVE-2026-9058

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-9058

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free