CVE Explorer
CVE-2026-44088
SzafirHost verifies the signature of the downloaded JAR file using class JarInputStream (reading from the beginning of the file), but loads classes using class JarFile/URLClassLoader (reading the Central Directory from the end). It can lead to remote code execution by allowing an attacker to combine a genuine, signed JAR file with a malicious ZIP file, causing the verification to pass but the malicious class to be loaded.
This issue was fixed in version 1.2.1.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"SzafirHost","vendor":"Krajowa Izba Rozliczeniowa","versions":[{"lessThan":"1.2.1","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:49d70bc7bca4581cf2d7ef5493f4fba07e4d7e4a4a8e352695458aa44598b0b9 · sha256:3950b8f9aeed7c80… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.6,"baseSeverity":"HIGH","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"LOW","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"ACTIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:49d70bc7bca4581cf2d7ef5493f4fba07e4d7e4a4a8e352695458aa44598b0b9 · sha256:3950b8f9aeed7c80… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-434","description":"CWE-434 Unrestricted Upload of File with Dangerous Type","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:49d70bc7bca4581cf2d7ef5493f4fba07e4d7e4a4a8e352695458aa44598b0b9 · sha256:3950b8f9aeed7c80… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["third-party-advisory"],"url":"https://cert.pl/posts/2026/05/CVE-2026-44088"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:49d70bc7bca4581cf2d7ef5493f4fba07e4d7e4a4a8e352695458aa44598b0b9 · sha256:3950b8f9aeed7c80… · /containers/cna/references/0
{"tags":["product"],"url":"https://www.elektronicznypodpis.pl/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:49d70bc7bca4581cf2d7ef5493f4fba07e4d7e4a4a8e352695458aa44598b0b9 · sha256:3950b8f9aeed7c80… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.