SB2026092928 - Multiple vulnerabilities in Wildfly Elytron



SB2026092928 - Multiple vulnerabilities in Wildfly Elytron

Published: September 29, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026092928
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Authentication Bypass by Spoofing (CVE-ID: CVE-2026-85511)

CWE-ID: CWE-290 - Authentication Bypass by Spoofing

CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass authentication controls.

The vulnerability exists due to missing URL encoding in the Elytron token realm OAuth2 introspection handling when processing token authentication requests. A remote user can provide specially crafted token values to bypass authentication controls.

Only token realms configured both to handle authentication and to validate tokens through an introspection endpoint are affected.


2) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-10832)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the DERDecoder class when processing a crafted DER payload containing an inflated length value. A remote attacker can send a specially crafted DER payload to cause a denial of service.

This affects services that process untrusted DER/ASN.1 input, including SASL authentication mechanisms and X.500 certificate principal parsing paths.


Remediation

Install update from vendor's website.