Improper Authorization in Apache CXF - CVE-2026-50628

 

Improper Authorization in Apache CXF - CVE-2026-50628

Published: August 25, 2026


Vulnerability identifier: #VU145225
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-50628
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass an IP binding security check.

The vulnerability exists due to improper access control in OAuthRequestFilter when processing requests with IP binding enabled. A remote user can send requests from an IP address other than the bound IP address to bypass an IP binding security check.

Only deployments with this security feature enabled are vulnerable.


Affected software

Apache CXF

How to mitigate CVE-2026-50628

Install security update from vendor's website.

Apache CXF - addressed in versions 4.1.7, 4.2.2

External References

Related Security Bulletins