---
schema: 1
kind: vulnerability
title: "CVE-2026-9058 — Szafir SDK (KIR): signature-verification routine reports success on an untrusted certificate chain, enabling auth bypass in Polish e-government"
headline: "CVE-2026-9058 — Szafir SDK (KIR): signature-verification routine reports success on an untrusted certificate chain, enabling auth bypass in Polish e-government"
summary: "CERT Polska discloses CVE-2026-9058 (CVSS 9.3), an auth-bypass in the Szafir e-signature SDK that underpins Polish public-sector identity — the SDK from clearinghouse KIR returns \"Positively verified\" (result code 0) from its signature-verification routine even when the signer's certificate chain is nondetermined (untrusted), so a consuming app that checks only the return code accepts a forged qualified signature. Any application that uses the SDK to accept qualified electronic signatures — the typical Polish e-government use case — is exposed; fixed in SDK version 463 (CERT Polska, 2026-05-25). A direct read-the-trust-status-not-the-return-code lesson for any European qualified-signature stack."
discovered_at: "2026-05-26T05:00:02Z"
event_date: 2026-05-25
run_id: 2026-05-26-ae9d0d4b
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - auth-bypass
  - pre-auth
  - identity
  - patch-available
  - enisa-critical
regions:
  - europe
sectors:
  - public-sector
  - healthcare
  - finance
entities: []
cves:
  - id: CVE-2026-9058
    cvss: "9.3"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
      - enisa-critical
sources:
  - url: "https://cert.pl/en/posts/2026/05/CVE-2026-9058/"
    publisher: "CERT Polska, 2026-05-25"
    role: primary
  - url: "https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-31679"
    publisher: "ENISA EUVD-2026-31679, 2026-05-25"
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Upgrade Szafir SDK to ≥ 463 and fix the validation logic, not just the version** — in every application consuming the SDK, gate signature acceptance on the certificate trust status (`SigningCertificate/@certificateType != \"nondetermined\"`), not on the result code alone, and review verification logs for `Result/@code == 0` events that coincided with a nondetermined certificate (§ 2, CVE-2026-9058). The same \"verify trust status, not just cryptographic integrity\" check applies to any CH/EU qualified-signature stack ([CERT Polska, 2026-05-25](https://cert.pl/en/posts/2026/05/CVE-2026-9058/))."
migrated_from: briefs/2026-05-26.md
---

CERT Polska disclosed CVE-2026-9058, an improper-certificate-validation flaw (CWE-393 / CWE-637) scored CVSS 4.0 **9.3** (`AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N`) in **Szafir SDK**, the qualified-electronic-signature library developed by clearinghouse Krajowa Izba Rozliczeniowa (KIR) and embedded across Polish public-administration systems ([CERT Polska, 2026-05-25](https://cert.pl/en/posts/2026/05/CVE-2026-9058/); [ENISA EUVD-2026-31679, 2026-05-25](https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-31679)). The defect is precise and instructive: the SDK returns the success code `/VerifyingTaskItem/Signature/VerificationResult/Result/@code == 0` ("Positively verified") from cryptographic signature verification **even when the signer certificate's trust status is `nondetermined`** — i.e. the chain could not be validated to a trusted root. A consuming application that gates on the result code alone treats a signature backed by an unverifiable or attacker-supplied certificate as valid, yielding authentication bypass and user impersonation without possession of a legitimate qualified certificate ([`T1606`](https://attack.mitre.org/techniques/T1606/)). Any application that consumes Szafir to accept qualified electronic signatures is therefore exposed to forged-signature acceptance — squarely the qualified-signature use case across Polish e-government and regulated industry; the issue is fixed in **version 463**.

This clears the § 2 bar on ENISA EUVD CVSS ≥ 9.0 and as a national-CERT primary disclosure for its own jurisdiction. Defender action beyond upgrading to ≥ 463: applications must validate the certificate **trust status independently of the result code** — check `…/SigningCertificate/@certificateType != "nondetermined"` before accepting the signature — and audit verification logs for events where `Result/@code == 0` coincided with a nondetermined certificate, which indicates likely abuse. The broader lesson generalises to any CH/EU qualified-signature stack: never collapse "cryptographically intact" and "anchored to a trusted root" into a single boolean. No in-the-wild exploitation is reported.
