Improper Authentication in Apache CXF - CVE-2026-50623
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to improper access control in the OAuth2 TokenIntrospectionService introspection endpoint when handling requests to /services/oauth2/introspect. A remote attacker can send a request to the endpoint to bypass authentication.
This issue is exposed if authentication was not enabled on the service.