CVE-2026-61466
published 2026-08-06CVE-2026-61466: In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration…
PriorityP354critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.42%
35.6th percentile
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 3.6.12 | 3.6.12 |
| apache | cxf | >= 4.0.0 < 4.1.8 | 4.1.8 |
| apache | cxf | >= 4.2.0 < 4.2.3 | 4.2.3 |
| apache_software_foundation | apache_cxf | < 3.6.12 | 3.6.12 |
| apache_software_foundation | apache_cxf | >= 4.0.0 < 4.1.8 | 4.1.8 |
| apache_software_foundation | apache_cxf | >= 4.2.0 < 4.2.3 | 4.2.3 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cxf: Apache CXF: Privilege Escalation via OAuth2 Dynamic Client Registration Scope Self-Assignment
vendor_redhat·2026-08-06·CVSS 9.1
CVE-2026-61466 [CRITICAL] CWE-266 cxf: Apache CXF: Privilege Escalation via OAuth2 Dynamic Client Registration Scope Self-Assignment
cxf: Apache CXF: Privilege Escalation via OAuth2 Dynamic Client Registration Scope Self-Assignment
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
A flaw was found in Apache CXF. The OAuth2 Dynamic Client Registration endpoint in Apache CXF does not properly validate the `scope` value provided during client registration. This oversight allows a malicious client to assign itself privileged access scopes, potentially leading to unauthor
GHSA
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it a
ghsa_unreviewed·2026-08-06
CVE-2026-61466 [CRITICAL] CWE-304 In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it a
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
No detection rules found.
No public exploits indexed.
2026-08-06
Published