Time-of-check Time-of-use (TOCTOU) Race Condition in Apache CXF - CVE-2026-50631
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to generate multiple valid access tokens from a single refresh token.
The vulnerability exists due to a race condition in AbstractOAuthDataProvider when processing concurrent refresh token requests. A remote user can replay a leaked refresh token concurrently to generate multiple valid access tokens from a single refresh token.
The issue occurs only when 'recycleRefreshTokens' is set to false.