OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-89135

MEDIUM · CVSS 6.5 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A vulnerability in OpenSSL allows an unverified attacker Certificate Authority (CA) to be permanently planted in the shared CertManager, which bypasses certificate validation across various consumers, including native TLS and OCSP. This issue affects wolfSSL versions 5.8.4 through 5.9.2 when built with specific macros or configurations that utilize the X509_verify_cert function. Organizations using these versions of wolfSSL should prioritize remediation to mitigate the risk of unauthorized access and potential man-in-the-middle attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-89135
Severity
MEDIUM
CVSS
6.5
EPSS
0.15%
OpenSSL

Original NVD Description

A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certificate validation in every type-blind sibling consumer (native TLS, OCSP, CRL, direct CM verify). This affects version 5.8.4 through 5.9.2 of wolfSSL with the macros (OPENSSL_EXTRA && !NO_CERTS && !WOLFCRYPT_ONLY) defined or built with --enable-opensslextra and the application is specifically making calls to the X509_verify_cert function.

Related CVEs

Other vulnerabilities affecting the same vendor(s)