CVE-2026-89102
Last modified
CVE-2026-89102 is a high-severity vulnerability rated 8.3/10 on the CVSS scale. In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to certificate forgery. When a wolfSSL client enables OCSP stapling with the HAVE_CERTIFICATE_STATUS_REQUEST_V2 feature and calls wolfSSL_UseOCSPStaplingV2(ssl, WOLFSSL_CSR2_OCSP_MULTI, options), the client accepts any certificate in the peer's chain as a certificate authority without verifying that the certificate is actually authorized to act as one.
Description
In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to certificate forgery. When a wolfSSL client enables OCSP stapling with the HAVE_CERTIFICATE_STATUS_REQUEST_V2 feature and calls wolfSSL_UseOCSPStaplingV2(ssl, WOLFSSL_CSR2_OCSP_MULTI, options), the client accepts any certificate in the peer's chain as a certificate authority without verifying that the certificate is actually authorized to act as one. This means that an attacker who possesses any certificate that chains to a CA trusted by the client (along with its private key) can forge certificates for arbitrary identities that will be accepted as valid by the client. The end entity certificate of the server is stored in the persistent trust store, affecting subsequent connections that reuse the context even when OCSP multi usage is not employed. Found by internal wolfSSL testing.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| wolfSSL | wolfSSL | >= 5.7.2, <= 5.9.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-89102?
How severe is CVE-2026-89102?
How do I fix CVE-2026-89102?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-89090An unrecovered panic in the event stream header decoder in A…5.9
- CVE-2026-89092The nscd service in the GNU C Library 2.3.4 onwards may cras…4.2
- CVE-2026-89093The Better Messages – Chat Rooms, Group Chat, Private Messag…5.3
- CVE-2026-89094Forgejo before 16.0.4 allows remote code execution via a cra…9.9
- CVE-2026-89099A race condition in the document value layer of MongoDB Serv…7.5
- CVE-2026-8910The WP Emoticon Rating plugin for WordPress is vulnerable to…6.1
- CVE-2026-8911The WP AutoBuzz plugin for WordPress is vulnerable to Cross-…6.1
- CVE-2026-8912The Contest Gallery plugin for WordPress is vulnerable to SQ…7.5
- CVE-2026-8913A command Injection vulnerability exists in the WireGuard cl…8.5
- CVE-2026-89133wolfSSL versions 5.9.2 and earlier contain a flaw in the X.5…6.3
- CVE-2026-89134A certificate with no dNSName SAN but another SAN type prese…6.3
- CVE-2026-89135A failed X509_verify_cert call permanently plants an unverif…6.3
Are you affected by CVE-2026-89102?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
