| CVE ID | CVE-2026-9058 |
| Publication date | 25 May 2026 |
| Vendor | Krajowa Izba Rozliczeniowa |
| Product | Szafir SDK |
| Vulnerable versions | All before 1.8.463.2 |
| Vulnerability type (CWE) |
Return of Wrong Status Code (CWE-393) Unnecessary Complexity in Protection Mechanism (Not Using 'Economy of Mechanism') (CWE-637) Improper Certificate Validation (CWE-295) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Szafir SDK software and participated in coordination of its disclosure.
23.07.2026 UPDATE: A CWE has been added and the description has been updated
The vulnerability CVE-2026-9058: For untrusted certificates that contain the Authority Information Access - caIssuers URI extension, Szafir SDK will automatically download the parent CA certificate from the specified URL and will import it to its trust store as a nonqualified certificate. In such a case, Szafir SDK returns a success status code of 0 (Positively verified) upon successful cryptographic verification and a certificate status of nonqualified.
For other types of untrusted certificates, Szafir SDK returns a success status code of 0 (Positively verified) upon successful cryptographic verification and a certificate status of nondetermined.
This may lead integrating applications to incorrectly treat the digital signature as valid despite an untrusted certificate chain. This flaw enables authentication bypass and user impersonation: (1) in use-cases other than qualified certificate authentication, or (2) if the qualified certificate authentication use-case is not correctly implemented by the integrating application.
This issue was fixed in version 1.8.463.2.
Credits
We thank Michał Leszczyński (icedev.pl) for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.