CVE-2026-50632
published 2026-06-12CVE-2026-50632: A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can…
PriorityP352high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.65%
47.2th percentile
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 4.1.7 | 4.1.7 |
| apache | cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cxf: org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Arbitrary code execution via untrusted JMS configuration
vendor_redhat·2026-06-12·CVSS 8.1
CVE-2026-50632 [HIGH] CWE-502 cxf: org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Arbitrary code execution via untrusted JMS configuration
cxf: org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Arbitrary code execution via untrusted JMS configuration
A flaw was found in Apache CXF. This vulnerability, stemming from an incomplete fix for a previous issue, allows untrusted users who can configure Java Message Service (JMS) for Apache CXF to achieve arbitrary code execution. This could lead to a complete compromise of the affected system.
Statement: This Important flaw in Apache CXF's JMS transport allows arbitrary code execution. The vulnerability occurs when untrusted users can configure Java Message Service (JMS) for Apache CXF, potentially leading to a complete system compromise. This risk is present in environments where JMS configuration is accessible to or managed by untrusted entities.
Mitigation: To mitigate this iss
GHSA
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrus
ghsa_unreviewed·2026-06-12·CVSS 7.5
CVE-2026-50632 [HIGH] CWE-20 A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrus
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
VulDB
Apache CXF up to 4.1.6/4.2.1 JNDI injection
vuldb·2026-06-11
CVE-2026-50632 [CRITICAL] Apache CXF up to 4.1.6/4.2.1 JNDI injection
A vulnerability, which was classified as critical, was found in Apache CXF up to 4.1.6/4.2.1. Affected by this issue is some unknown functionality of the component JNDI. The manipulation results in injection.
This vulnerability is known as CVE-2026-50632. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
2026-06-12
Published