{"id":"CVE-2026-50623","aliases":["GHSA-542g-m3fx-q86f"],"url":"https://o3.security/vulnerability/CVE-2026-50623","summary":"Apache CXF: Authentication Bypass in OAuth2 TokenIntrospectionService","details":"An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker. However note that this is a safeguard only in the case that someone forgot to enable authentication on the service. Users are recommended to upgrade to version 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.","published":"2026-06-12T08:52:05.767Z","modified":"2026-08-20T18:48:08.881180372Z","cvss":{"score":4.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.cxf:cxf-rt-rs-security-oauth2","fixedVersion":"4.2.2"},{"ecosystem":"Maven","name":"org.apache.cxf:cxf-rt-rs-security-oauth2","fixedVersion":"4.1.7"}],"fix":null,"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/06/11/3"},{"type":"WEB","url":"https://repo.maven.apache.org/maven2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50623.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/ydzj8m5mqmjy13xgyj9mkk9hfff63qq7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50623"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-20T18:48:08.881180372Z"}}