9.8
CVE-2026-68079
- EPSS 0.41%
- Veröffentlicht 06.08.2026 11:22:57
- Zuletzt bearbeitet 07.08.2026 00:16:39
- CVE-Watchlists
- Unerledigt
Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.41% | 0.339 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-294 Authentication Bypass by Capture-replay
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
https://lists.apache.org/thread/6m06gdqz4rxhy9g90qz9lyqx2gqmf13o
http://www.openwall.com/lists/oss-security/2026/08/06/24