CVE-2026-50631
published 2026-06-12CVE-2026-50631: A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple…
PriorityP349high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.29%
21.3th percentile
A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed concurrently by multiple attackers or threads. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 4.1.7 | 4.1.7 |
| apache | cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
| apache_software_foundation | apache_cxf | < 4.1.7 | 4.1.7 |
| apache_software_foundation | apache_cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshToke
ghsa_unreviewed·2026-06-12
CVE-2026-50631 [HIGH] CWE-367 A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshToke
A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed concurrently by multiple attackers or threads. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
VulDB
Apache CXF up to 4.1.6/4.2.1 OAuth2 toctou
vuldb·2026-06-11
CVE-2026-50631 [LOW] Apache CXF up to 4.1.6/4.2.1 OAuth2 toctou
A vulnerability, which was classified as problematic, has been found in Apache CXF up to 4.1.6/4.2.1. Affected by this vulnerability is an unknown functionality of the component OAuth2. The manipulation leads to time-of-check time-of-use.
This vulnerability is traded as CVE-2026-50631. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-12
Published