CVE-2026-9058: CWE-637 Unnecessary Complexity in Protection Mechanism (Not Using 'Economy of Mechanism') in Krajowa Izba Rozliczeniowa Szafir SDK
For untrusted certificates that contain the "Authority Information Access - caIssuers URI" extension, Szafir SDK will automatically download the parent CA certificate from the specified URL and will import it to its trust store as a "nonqualified" certificate. In such a case, Szafir SDK returns a success status code of 0 ("Positively verified") upon successful cryptographic verification and a certificate status of "nonqualified". For other types of untrusted certificates, Szafir SDK returns a success status code of 0 ("Positively verified") upon successful cryptographic verification and a certificate status of "nondetermined". This may lead integrating applications to incorrectly treat the digital signature as valid despite an untrusted certificate chain. This flaw enables authentication bypass and user impersonation: (1) in use-cases other than qualified certificate authentication, or (2) if the qualified certificate authentication use-case is not correctly implemented by the integrating application. This issue was fixed in version 1.8.463.2.
AI Analysis
Technical Summary
The Szafir SDK automatically downloads and imports parent CA certificates from the 'caIssuers URI' extension in untrusted certificates as 'nonqualified' certificates, returning a success verification status. For other untrusted certificates, it returns a success status with a 'nondetermined' certificate status. This behavior may cause integrating applications to incorrectly accept digital signatures as valid despite untrusted certificate chains, enabling authentication bypass and user impersonation in scenarios outside qualified certificate authentication or if the application does not properly implement qualified certificate authentication. The vulnerability is fixed in Szafir SDK version 1.8.463.2.
Potential Impact
This vulnerability allows attackers to bypass authentication and impersonate users by exploiting the SDK's incorrect handling of untrusted certificates with the 'caIssuers URI' extension. Applications relying on the SDK may incorrectly treat untrusted certificates as valid, leading to potential unauthorized access or actions.
Mitigation Recommendations
A fix is available in Szafir SDK version 1.8.463.2. Users and integrators should upgrade to this version to remediate the vulnerability. No other mitigation guidance is provided or required as the issue is resolved by the official fix.
CVE-2026-9058: CWE-637 Unnecessary Complexity in Protection Mechanism (Not Using 'Economy of Mechanism') in Krajowa Izba Rozliczeniowa Szafir SDK
Description
For untrusted certificates that contain the "Authority Information Access - caIssuers URI" extension, Szafir SDK will automatically download the parent CA certificate from the specified URL and will import it to its trust store as a "nonqualified" certificate. In such a case, Szafir SDK returns a success status code of 0 ("Positively verified") upon successful cryptographic verification and a certificate status of "nonqualified". For other types of untrusted certificates, Szafir SDK returns a success status code of 0 ("Positively verified") upon successful cryptographic verification and a certificate status of "nondetermined". This may lead integrating applications to incorrectly treat the digital signature as valid despite an untrusted certificate chain. This flaw enables authentication bypass and user impersonation: (1) in use-cases other than qualified certificate authentication, or (2) if the qualified certificate authentication use-case is not correctly implemented by the integrating application. This issue was fixed in version 1.8.463.2.
CVSS v4.0
Score 9.3critical
Affected software
pkg:github/krajowa-izba-rozliczeniowa/szafir-sdkRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Szafir SDK automatically downloads and imports parent CA certificates from the 'caIssuers URI' extension in untrusted certificates as 'nonqualified' certificates, returning a success verification status. For other untrusted certificates, it returns a success status with a 'nondetermined' certificate status. This behavior may cause integrating applications to incorrectly accept digital signatures as valid despite untrusted certificate chains, enabling authentication bypass and user impersonation in scenarios outside qualified certificate authentication or if the application does not properly implement qualified certificate authentication. The vulnerability is fixed in Szafir SDK version 1.8.463.2.
Potential Impact
This vulnerability allows attackers to bypass authentication and impersonate users by exploiting the SDK's incorrect handling of untrusted certificates with the 'caIssuers URI' extension. Applications relying on the SDK may incorrectly treat untrusted certificates as valid, leading to potential unauthorized access or actions.
Mitigation Recommendations
A fix is available in Szafir SDK version 1.8.463.2. Users and integrators should upgrade to this version to remediate the vulnerability. No other mitigation guidance is provided or required as the issue is resolved by the official fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERT-PL
- Date Reserved
- 2026-05-20T06:36:10.929Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a145147a5ae1af1aaa32f6b
Added to database: 05/25/2026, 13:40:23 UTC
Last enriched: 07/23/2026, 21:31:39 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 73
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.