Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
Published Aug 6, 2026
7.5
HIGHCVSS 3.1
EPSS 0.66%
Description
In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked token MUST return {"active":false}'. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Affected products
-
- Version 0StatusaffectedConstraints<3.6.12
- Version 4.0.0StatusaffectedConstraints<4.1.8
- Version 4.2.0StatusaffectedConstraints<4.2.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache CXF | unaffected |
|
No data.
Red Hat JBoss Enterprise Application Platform Expansion Pack
cxf-rt-rs-security-oauth2
Fix deferred
Red Hat JBoss Web Server 5
cxf-rt-rs-security-oauth2
Fix deferred
Red Hat build of Apache Camel for Spring Boot 4
cxf-rt-rs-security-oauth2
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform Expansion Pack | cxf-rt-rs-security-oauth2 | Fix deferred | n/a |
| Red Hat JBoss Web Server 5 | cxf-rt-rs-security-oauth2 | Fix deferred | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | cxf-rt-rs-security-oauth2 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Moderate: This flaw in Apache CXF's OAuth2 token handling allows previously revoked access and refresh tokens to remain valid. This bypasses intended revocation mechanisms, potentially enabling unauthorized access to resources in applications deployed on affected Red Hat platforms that utilize the DefaultEncryptingOAuthDataProvider.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (7)
- http://www.openwall.com/lists/oss-security/2026/08/06/25
- https://access.redhat.com/security/cve/CVE-2026-68481 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2511994 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53857 Advisory
- https://lists.apache.org/thread/88c0h10yjb2b8201o1km3st71fs2zw2b vendor-advisoryMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-68481
- https://www.cve.org/CVERecord?id=CVE-2026-68481
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/08/06/25 | ||
| https://access.redhat.com/security/cve/CVE-2026-68481 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2511994 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53857 | Advisory | |
| https://lists.apache.org/thread/88c0h10yjb2b8201o1km3st71fs2zw2b | vendor-advisoryMailing ListVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-68481 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-68481 |
Change history (0)
No recorded changes yet.