CVE-2026-68481

HIGH

Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider

Title source: cna
STIX 2.1

Description

In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked token MUST return {"active":false}'. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0043
EPSS Percentile 35.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-672
Status published
Products (4)
apache/cxf < 3.6.12
Apache Software Foundation/Apache CXF < 3.6.12
Apache Software Foundation/Apache CXF 4.0.0 - 4.1.8
Apache Software Foundation/Apache CXF 4.2.0 - 4.2.3
Published Aug 06, 2026
Tracked Since Aug 06, 2026