Improper Authentication in Apache CXF - CVE-2026-65583
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to improper access control in the OIDC relying-party token validator when processing self-issued ID tokens. A remote attacker can supply a crafted token to bypass authentication.
Self-issued ID tokens are not accepted by default in the validator.