CVE-2026-68079
published 2026-08-06CVE-2026-68079: In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.40%
32.9th percentile
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 3.6.12 | 3.6.12 |
| apache | cxf | — | — |
| apache | cxf | >= 4.0.0 < 4.1.8 | 4.1.8 |
| apache | cxf | >= 4.2.0 < 4.2.3 | 4.2.3 |
| apache_software_foundation | apache_cxf | < 3.6.12 | 3.6.12 |
| apache_software_foundation | apache_cxf | >= 4.0.0 < 4.1.8 | 4.1.8 |
| apache_software_foundation | apache_cxf | >= 4.2.0 < 4.2.3 | 4.2.3 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality.
ghsa_unreviewed·2026-08-06
CVE-2026-68079 [CRITICAL] CWE-294 In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality.
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Red Hat
org.apache.cxf/cxf: Apache CXF: Authorization code replay due to flaw in DefaultEncryptingCodeDataProvider
vendor_redhat·2026-08-06·CVSS 9.8
CVE-2026-68079 [CRITICAL] CWE-613 org.apache.cxf/cxf: Apache CXF: Authorization code replay due to flaw in DefaultEncryptingCodeDataProvider
org.apache.cxf/cxf: Apache CXF: Authorization code replay due to flaw in DefaultEncryptingCodeDataProvider
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
A flaw was found in Apache CXF's DefaultEncryptingCodeDataProvider. This vulnerability allows a remote attacker to redeem a captured authorization code an unlimited number of times. The flaw exists due to an issue in the `removeCodeGrant` functionality, which fails to properly invalidate used authori
No detection rules found.
No public exploits indexed.
2026-08-06
Published