cbcvebase.
CVE-2026-50623
published 2026-06-12

CVE-2026-50623: An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context…

PriorityP432medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EPSS
0.37%
29.4th percentile
An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker. However note that this is a safeguard only in the case that someone forgot to enable authentication on the service. Users are recommended to upgrade to version 4.2.2 or 4.1.7, which fixes this issue.

Affected

4 ranges
VendorProductVersion rangeFixed in
apachecxf< 4.1.74.1.7
apachecxf>= 4.2.0 < 4.2.24.2.2
apache_software_foundationapache_cxf< 4.1.74.1.7
apache_software_foundationapache_cxf>= 4.2.0 < 4.2.24.2.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.