CVE-2026-44417
published 2026-06-12CVE-2026-44417: A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can…
PriorityP351high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
0.64%
47.0th percentile
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 4.1.7 | 4.1.7 |
| apache | cxf | < 3.6.11 | 3.6.11 |
| apache | cxf | — | — |
| apache | cxf | >= 4.0.0 < 4.1.6 | 4.1.6 |
| apache | cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
| apache_software_foundation | apache_cxf | < 3.6.11 | 3.6.11 |
| apache_software_foundation | apache_cxf | < 4.1.7 | 4.1.7 |
| apache_software_foundation | apache_cxf | >= 4.0.0 < 4.1.6 | 4.1.6 |
| apache_software_foundation | apache_cxf | >= 4.2.0 < 4.2.1 | 4.2.1 |
| apache_software_foundation | apache_cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
cvelistv5v3.19.8CRITICALCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa9.8CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrus
ghsa_unreviewed·2026-06-12·CVSS 7.5
CVE-2026-50632 [HIGH] CWE-20 A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrus
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
GHSA
GHSA-2hvc-5c6v-f533: The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead
ghsa_unreviewed·2026-05-26·CVSS 9.8
CVE-2026-44417 [CRITICAL] CWE-20 GHSA-2hvc-5c6v-f533: The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
GHSA
Apache CXF: Untrusted JMS configuration can lead to RCE
ghsa·2026-05-26·CVSS 9.8
CVE-2026-44417 [CRITICAL] CWE-20 Apache CXF: Untrusted JMS configuration can lead to RCE
Apache CXF: Untrusted JMS configuration can lead to RCE
The fix for CVE-2025-48913: `Apache CXF: Untrusted JMS configuration can lead to RCE` was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CVEList
Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)
cvelistv5·2026-05-22·CVSS 9.8
CVE-2026-44417 [CRITICAL] CWE-20 Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)
Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
VulDB
Apache CXF up to 3.6.10/4.1.5/4.2.0 JMS Configuration input validation (WID-SEC-2026-1659)
vuldb·2026-05-22
CVE-2026-44417 [CRITICAL] Apache CXF up to 3.6.10/4.1.5/4.2.0 JMS Configuration input validation (WID-SEC-2026-1659)
A vulnerability identified as critical has been detected in Apache CXF up to 3.6.10/4.1.5/4.2.0. The impacted element is an unknown function of the component JMS Configuration Handler. This manipulation causes improper input validation.
This vulnerability is registered as CVE-2026-44417. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
Red Hat
org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration
vendor_redhat·2026-05-22·CVSS 7.5
CVE-2026-44417 [HIGH] CWE-15 org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration
org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration
A flaw was found in Apache CXF. Untrusted users, if allowed to configure Java Message Service (JMS) for Apache CXF, can exploit this vulnerability to achieve remote code execution (RCE). This issue arises from an incomplete fix for a prior security flaw, indicating an alternative path that could lead to code execution.
Statement: This is an Important flaw in Apache CXF where an incomplete fix for a prior vulnerability allows remote code execution. Exploitation requires that untrusted users have permissions to configure Java Message Service (JMS) within the Apache CXF environment, which is not a default configuration in Red Hat products. Successful exploitation could lead to arbitrary c
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-50632 cxf: org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Arbitrary code execution via untrusted JMS configuration
bugzilla·2026-06-12·CVSS 7.5
CVE-2026-50632 [HIGH] CVE-2026-50632 cxf: org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Arbitrary code execution via untrusted JMS configuration
CVE-2026-50632 cxf: org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Arbitrary code execution via untrusted JMS configuration
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
Bugzilla
CVE-2026-44417 org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration
bugzilla·2026-05-22·CVSS 9.8
CVE-2026-44417 [CRITICAL] CVE-2026-44417 org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration
CVE-2026-44417 org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
2026-06-12
Published