CVE-2026-68481: In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh
In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked token MUST return {"active":false}'. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-68481
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-68481 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for In Apache CXF's
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCVE-2026-68079: In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeem…nvd · 2026-08-06
- criticalCVE-2026-65583: Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without en…nvd · 2026-08-06
- criticalCVE-2026-63687: Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authori…nvd · 2026-08-06
- criticalCVE-2026-61466: In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts …nvd · 2026-08-06
- medium[NEW] [medium] Apache CXF: Multiple Vulnerabilitiescert-bund · 2026-08-06
- criticalCVE-2026-66909: Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native…nvd · 2026-08-06
More from NVD Recent CVEs
- criticalCVE-2026-70332: Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attac…2026-08-07
- criticalCVE-2026-68823: Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacke…2026-08-07
- highCVE-2026-65668: Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to eleva…2026-08-07
- criticalCVE-2026-65667: Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges…2026-08-07
- criticalCVE-2026-63508: Missing authentication for critical function in Microsoft Planetary Computer Pro allows an una…2026-08-07