openwall.com
http://www.openwall.com/lists/oss-security/2026/08/06/21 CVE-2026-61466
CRITICAL
Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
Record summary
CVE-2026-61466 has a selected CVSS score of 9.1 (critical).
Description
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 3.6.12 | affected |
| 4.0.0 to < 4.1.8 | affected | ||
| 4.2.0 to < 4.2.3 | affected |
References
3lists.apache.orgVendor advisory
https://lists.apache.org/thread/2l1r16g79tpxd7fzrzr2q9oscwrjgljs nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-61466