CVE-2026-65583
cxf: Insufficient Verification of Data Authenticity (CVE-2026-65583)
Affected
- apache/cxf
lt *..3.6.12 - apache/cxf
between 4.0.0..4.1.8 - apache/cxf
between 4.2.0..4.2.3
Description
Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fixes this issue.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
4.0.0 – 4.1.84.2.0 – 4.2.33.6.12fixed from 3.6.12Metrics
Show all metrics
Weakness classes (CWE)
CWE-345Class
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-08-07 00:16 UTC· af854a3a-2127-422b-91ae-364da2661108
- Reference: http://www.openwall.com/lists/oss-security/2026/08/06/23
- Initial Analysis2026-08-06 18:41 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* versions up to (excluding) 3.6.12 *cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* versions from (including) 4.0.0 up to (excluding) 4.1.8 *cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* versions from (including) 4.2.0 up to (excluding) 4.2.3
- Reference Type: Apache Software Foundation: https://lists.apache.org/thread/fzj8yzgfl53gclxrcdrnrx3grcpkq51j Types: Mailing List, Vendor Advisory
- CVE Modified2026-08-06 16:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- SSVC: {"id":"CVE-2026-65583","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
- New CVE Received2026-08-06 12:16 UTC· security@apache.org
- Affected: Apache CXF
- Description: Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fixes this issue.
- CWE: CWE-345
- Reference: https://lists.apache.org/thread/fzj8yzgfl53gclxrcdrnrx3grcpkq51j