Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache CXF - CVE-2026-50633
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to jndi injection in DispatchMDBMessageListenerImpl when processing a manipulated JCA deployment descriptor or runtime activation parameters. A remote user can modify the ra.xml deployment descriptor or activation parameters to execute arbitrary code.