Improper Certificate Validation in wolfSSL - CVE-2026-89135
Published: October 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass certificate validation in sibling consumers.
The vulnerability exists due to improper certificate validation in X509_verify_cert when a certificate verification attempt fails. A remote attacker can cause a failed certificate verification that adds an unverified CA to the shared certificate manager to bypass certificate validation in sibling consumers.
The issue requires an application using X509_verify_cert in an OPENSSL_EXTRA build.