Improper Authorization in Apache CXF - CVE-2026-50628
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to bypass an IP binding security check.
The vulnerability exists due to improper access control in OAuthRequestFilter when processing requests with IP binding enabled. A remote user can send requests from an IP address other than the bound IP address to bypass an IP binding security check.
Only deployments with this security feature enabled are vulnerable.