CVE-2026-65583

cxf: Insufficient Verification of Data Authenticity (CVE-2026-65583)

criticalEPSS 0.3%

Affected

  • apache/cxf lt *..3.6.12
  • apache/cxf between 4.0.0..4.1.8
  • apache/cxf between 4.2.0..4.2.3

Description

Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fixes this issue.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

apachecxf
4.0.0 – 4.1.84.2.0 – 4.2.33.6.12fixed from 3.6.12

Metrics

9.1
Source: cna-v3
18.7 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
critical
no public PoC known
0.3 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-06 11:23 UTC
CWE-345

Weakness classes (CWE)

  • CWE-345Class

    Insufficient Verification of Data Authenticity

    The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-07 00:16 UTC· af854a3a-2127-422b-91ae-364da2661108
    • Reference: http://www.openwall.com/lists/oss-security/2026/08/06/23
  2. Initial Analysis2026-08-06 18:41 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* versions up to (excluding) 3.6.12 *cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* versions from (including) 4.0.0 up to (excluding) 4.1.8 *cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* versions from (including) 4.2.0 up to (excluding) 4.2.3
    • Reference Type: Apache Software Foundation: https://lists.apache.org/thread/fzj8yzgfl53gclxrcdrnrx3grcpkq51j Types: Mailing List, Vendor Advisory
  3. CVE Modified2026-08-06 16:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
    • SSVC: {"id":"CVE-2026-65583","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
  4. New CVE Received2026-08-06 12:16 UTC· security@apache.org
    • Affected: Apache CXF
    • Description: Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fixes this issue.
    • CWE: CWE-345
    • Reference: https://lists.apache.org/thread/fzj8yzgfl53gclxrcdrnrx3grcpkq51j

Linked advisories