# Szafir SDK signature bypass patched in v463

Published: 2026-05-25 · Severity: high
Canonical: https://vorant.io/reports/ae10aaff-3319-54a6-938d-8123cfe9b2e5/szafir-sdk-signature-bypass-patched-in-v463

> CVE-2026-9058 in Szafir SDK allowed authentication bypass by returning success for signatures with unverified certificate chains; fixed in version 463.

CERT Polska has disclosed CVE-2026-9058, a vulnerability in Szafir SDK software that enables authentication bypass through improper signature verification. The flaw causes the SDK to return a success status code during digital signature verification even when the trust status of the signer's certificate cannot be established. Applications consuming the SDK's verification results would incorrectly treat signatures as valid despite unverified certificate chains, allowing attackers to bypass authentication controls and potentially impersonate legitimate users.

The vulnerability was responsibly disclosed by Michał Leszczyński of icedev.pl and has been addressed in Szafir SDK version 463. Organizations using earlier versions should upgrade immediately to prevent exploitation. The issue represents a critical failure in the cryptographic verification chain that could undermine the integrity of any authentication or signing workflows dependent on the affected SDK.

## Mentioned in this report

- Vulnerabilities: CVE-2026-9058

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-9058

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ae10aaff-3319-54a6-938d-8123cfe9b2e5/szafir-sdk-signature-bypass-patched-in-v463.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
