SB2026070266 - Multiple vulnerabilities in Apache CXF



SB2026070266 - Multiple vulnerabilities in Apache CXF

Published: July 2, 2026 Updated: August 25, 2026

Security Bulletin ID SB2026070266
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 11
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 55% Low 45%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 11 vulnerabilities.


1) Resource exhaustion (CVE-ID: CVE-2026-50645)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to there is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


2) XML External Entity injection (CVE-ID: CVE-2026-49875)

CWE-ID: CWE-611 - Improper Restriction of XML External Entity Reference ('XXE')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper restriction of XML external entity reference in W3CMultiSchemaFactory and EndpointReferenceUtils when parsing XML input. A remote attacker can supply crafted XML containing external entity references to disclose sensitive information.

The issue enables out-of-band external entity resolution.


3) Improper Authentication (CVE-ID: CVE-2026-50623)

CWE-ID: CWE-287 - Improper Authentication

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authentication.

The vulnerability exists due to improper access control in the OAuth2 TokenIntrospectionService introspection endpoint when handling requests to /services/oauth2/introspect. A remote attacker can send a request to the endpoint to bypass authentication.

This issue is exposed if authentication was not enabled on the service.


4) Improper access control (CVE-ID: CVE-2026-50627)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to replay JWT access tokens against a different resource server.

The vulnerability exists due to improper access control in the JwtAccessTokenValidator class when validating incoming JWT access tokens. A remote user can present a valid JWT issued for one resource server to replay JWT access tokens against a different resource server.


5) Improper Authorization (CVE-ID: CVE-2026-50628)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass an IP binding security check.

The vulnerability exists due to improper access control in OAuthRequestFilter when processing requests with IP binding enabled. A remote user can send requests from an IP address other than the bound IP address to bypass an IP binding security check.

Only deployments with this security feature enabled are vulnerable.


6) Improper Output Neutralization for Logs (CVE-ID: CVE-2026-50629)

CWE-ID: CWE-117 - Improper Output Neutralization for Logs

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to inject arbitrary content into log files.

The vulnerability exists due to improper neutralization of special elements used in a log entry in the OAuth2 server logging of the clientId parameter when handling incoming HTTP requests. A remote attacker can supply a crafted client identifier containing control characters to inject arbitrary content into log files.

Injected content may include fake log entries.


7) HTTP response splitting (CVE-ID: CVE-2026-50630)

CWE-ID: CWE-113 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to inject arbitrary HTTP headers or split the HTTP response entirely.

The vulnerability exists due to crlf injection in the OAuth2 AuthorizationUtils class when constructing the WWW-Authenticate response header with an attacker-controlled realm value. A remote attacker can supply a crafted realm value to inject arbitrary HTTP headers or split the HTTP response entirely.


8) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-50631)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to generate multiple valid access tokens from a single refresh token.

The vulnerability exists due to a race condition in AbstractOAuthDataProvider when processing concurrent refresh token requests. A remote user can replay a leaked refresh token concurrently to generate multiple valid access tokens from a single refresh token.

The issue occurs only when 'recycleRefreshTokens' is set to false.


9) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2026-50632)

CWE-ID: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper control of externally referenced resources in JMSConfigFactory when processing untrusted JMS configuration. A remote user can supply crafted JMS configuration to execute arbitrary code.

Exploitation requires that untrusted users are allowed to configure JMS.


10) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2026-50633)

CWE-ID: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to jndi injection in DispatchMDBMessageListenerImpl when processing a manipulated JCA deployment descriptor or runtime activation parameters. A remote user can modify the ra.xml deployment descriptor or activation parameters to execute arbitrary code.


11) Insufficient verification of data authenticity (CVE-ID: CVE-2026-50634)

CWE-ID: CWE-345 - Insufficient Verification of Data Authenticity

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to influence downstream request parsing and signed-header consistency checks.

The vulnerability exists due to improper authentication in JwsJsonContainerRequestFilter when processing WS JSON requests with multiple signature entries. A remote user can supply a request in which metadata is taken from an unvalidated first signature entry to influence downstream request parsing and signed-header consistency checks.

The issue affects assumptions that accepted Content-Type or protected HTTP-header metadata came from the accepted signature entry.


Remediation

Install update from vendor's website.