Record summary

CVE-2026-61466 has a selected CVSS score of 9.1 (critical).

Description

In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Apache CXF

Browse Apache Software Foundation / Apache CXForg.apache.cxf:cxf-rt-rs-security-oauth2

Default status: unaffected

CVE ListBefore 3.6.12affected
4.0.0 to < 4.1.8affected
4.2.0 to < 4.2.3affected

References

3