CVE-2026-50633
published 2026-06-12CVE-2026-50633: A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to…
PriorityP350high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.83%
53.5th percentile
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 4.1.7 | 4.1.7 |
| apache | cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
| apache_software_foundation | apache_cxf | < 4.1.7 | 4.1.7 |
| apache_software_foundation | apache_cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
apache-cxf: org.apache.cxf/cxf-integration-jca: Apache CXF: Arbitrary code execution via JNDI Injection
vendor_redhat·2026-06-12·CVSS 8.1
CVE-2026-50633 [HIGH] CWE-502 apache-cxf: org.apache.cxf/cxf-integration-jca: Apache CXF: Arbitrary code execution via JNDI Injection
apache-cxf: org.apache.cxf/cxf-integration-jca: Apache CXF: Arbitrary code execution via JNDI Injection
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
A flaw was found in Apache CXF's JCA integration module. This Java Naming and Directory Interface (JNDI) Injection vulnerability allows for arbitrary code execution. A remote attacker could exploit this by manipulating the Java EE Connector Architecture (JCA) deployment descriptor (ra.xml) or runtime activation parameters, leading to the execution of malicious code on t
GHSA
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xm
ghsa_unreviewed·2026-06-12
CVE-2026-50633 [CRITICAL] CWE-20 A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xm
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
VulDB
Apache CXF up to 4.1.6/4.2.1 JNDI DispatchMDBMessageListenerImpl injection
vuldb·2026-06-11
CVE-2026-50633 [CRITICAL] Apache CXF up to 4.1.6/4.2.1 JNDI DispatchMDBMessageListenerImpl injection
A vulnerability has been found in Apache CXF up to 4.1.6/4.2.1 and classified as critical. This affects the function DispatchMDBMessageListenerImpl of the component JNDI Handler. This manipulation causes injection.
This vulnerability is handled as CVE-2026-50633. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread/1czhgovkgzdkyp3t61wthn0foogh2grfhttp://www.openwall.com/lists/oss-security/2026/06/11/10https://access.redhat.com/errata/RHSA-2026:37390https://access.redhat.com/security/cve/CVE-2026-50633https://bugzilla.redhat.com/show_bug.cgi?id=2488307https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50633.json
2026-06-12
Published