CVE-2026-50628
published 2026-06-12CVE-2026-50628: A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.67%
47.8th percentile
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this
security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 4.1.7 | 4.1.7 |
| apache | cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
| apache_software_foundation | apache_cxf | < 4.1.7 | 4.1.7 |
| apache_software_foundation | apache_cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address.
ghsa_unreviewed·2026-06-12
CVE-2026-50628 CWE-20 A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address.
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this
security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
VulDB
Apache CXF up to 4.1.6/4.2.1 OAuth2 access control
vuldb·2026-06-11
CVE-2026-50628 [CRITICAL] Apache CXF up to 4.1.6/4.2.1 OAuth2 access control
A vulnerability described as critical has been identified in Apache CXF up to 4.1.6/4.2.1. This affects an unknown function of the component OAuth2. Such manipulation leads to improper access controls.
This vulnerability is documented as CVE-2026-50628. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
Red Hat
cxf: org.apache.cxf/cxf-rt-rs-security-oauth2: cxf: Unauthorized access due to logic error in OAuthRequestFilter
vendor_redhat·2026-06-12·CVSS 9.8
CVE-2026-50628 [CRITICAL] CWE-358 cxf: org.apache.cxf/cxf-rt-rs-security-oauth2: cxf: Unauthorized access due to logic error in OAuthRequestFilter
cxf: org.apache.cxf/cxf-rt-rs-security-oauth2: cxf: Unauthorized access due to logic error in OAuthRequestFilter
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this
security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
A flaw was found in the OAuthRequestFilter component of cxf. A logic error in this filter inadvertently creates an inverse security check when enabled. This issue causes legitimate requests from a bound IP address to be rejected, while requests from any other IP address are blindly allowed. This could lead to unauthorized access to resources.
Statement: T
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread/vb3ho8lf228gh90m1fpnohf2008xrdxkhttp://www.openwall.com/lists/oss-security/2026/06/11/5https://access.redhat.com/errata/RHSA-2026:37390https://access.redhat.com/security/cve/CVE-2026-50628https://bugzilla.redhat.com/show_bug.cgi?id=2488302https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50628.json
2026-06-12
Published