CVE-2026-50627
published 2026-06-12CVE-2026-50627: The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one…
PriorityP351critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
EPSS
0.45%
36.0th percentile
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 4.1.7 | 4.1.7 |
| apache | cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
| apache_software_foundation | apache_cxf | < 4.1.7 | 4.1.7 |
| apache_software_foundation | apache_cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
apache-cxf: org.apache.cxf/cxf-rt-rs-security-oauth2: Apache CXF: Token Confusion/Routing attacks due to improper validation of JWT audience claims
vendor_redhat·2026-06-12·CVSS 9.1
CVE-2026-50627 [CRITICAL] CWE-303 apache-cxf: org.apache.cxf/cxf-rt-rs-security-oauth2: Apache CXF: Token Confusion/Routing attacks due to improper validation of JWT audience claims
apache-cxf: org.apache.cxf/cxf-rt-rs-security-oauth2: Apache CXF: Token Confusion/Routing attacks due to improper validation of JWT audience claims
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
A flaw was found in Apache CXF. The `JwtAccessTokenValidator` class fails to properly validate the 'aud' (Audience) claims within incoming JSON Web Token (JWT) access tokens. This vulnerability allows an attacker to reuse a JWT, originally intended for one resource serve
GHSA
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens.
ghsa_unreviewed·2026-06-12
CVE-2026-50627 CWE-289 The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens.
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
VulDB
Apache CXF up to 4.1.6/4.2.1 OAuth2 access control
vuldb·2026-06-11
CVE-2026-50627 [CRITICAL] Apache CXF up to 4.1.6/4.2.1 OAuth2 access control
A vulnerability marked as critical has been reported in Apache CXF up to 4.1.6/4.2.1. The impacted element is an unknown function of the component OAuth2. This manipulation causes improper access controls.
This vulnerability is registered as CVE-2026-50627. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread/0jfzz9q992957b99tw7hodcqjfyxwb1mhttp://www.openwall.com/lists/oss-security/2026/06/11/4https://access.redhat.com/errata/RHSA-2026:37390https://access.redhat.com/security/cve/CVE-2026-50627https://bugzilla.redhat.com/show_bug.cgi?id=2488298https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50627.json
2026-06-12
Published