7.5
CVE-2026-68481
- EPSS 0.43%
- Veröffentlicht 06.08.2026 11:22:37
- Zuletzt bearbeitet 07.08.2026 00:16:40
- CVE-Watchlists
- Unerledigt
Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked token MUST return {"active":false}'. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.351 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-672 Operation on a Resource after Expiration or Release
The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.
https://lists.apache.org/thread/88c0h10yjb2b8201o1km3st71fs2zw2b
http://www.openwall.com/lists/oss-security/2026/08/06/25