THREAT OPS › Threat News › [NVD] CVE-2026-41000 (LOW 3.7) — Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics
[NVD] CVE-2026-41000 (LOW 3.7) — Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics
CVE-2026-41000 CVSS: 3.7 LOW Published: 2026-06-11T07:16:28.037
Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when operators configured a r
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-41000cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-41000