Improper Authentication in Apache CXF - CVE-2026-57817
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject or substitute an authorization code.
The vulnerability exists due to improper authentication in the OIDC relying party hybrid flow implementation when processing hybrid flow responses from a non-compliant or misconfigured identity provider that omits the c_hash parameter. A remote attacker can supply a substituted authorization code to inject or substitute an authorization code.
Exploitation requires integration with an identity provider that omits the c_hash parameter in the hybrid OIDC flow.