Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache CXF - CVE-2026-50632
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper control of externally referenced resources in JMSConfigFactory when processing untrusted JMS configuration. A remote user can supply crafted JMS configuration to execute arbitrary code.
Exploitation requires that untrusted users are allowed to configure JMS.