CVE-2026-68079
cxf: Authentication Bypass by Capture-replay (CVE-2026-68079)
Affected
- apache/cxf
lt *..3.6.12 - apache/cxf
between 4.0.0..4.1.8 - apache/cxf
between 4.2.0..4.2.3
Description
A flaw was found in Apache CXF's DefaultEncryptingCodeDataProvider. This vulnerability allows a remote attacker to redeem a captured authorization code an unlimited number of times. The flaw exists due to an issue in the `removeCodeGrant` functionality, which fails to properly invalidate used authorization codes. This can lead to unauthorized access or session hijacking, violating the security principle that authorization codes should only be used once.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
4.0.0 – 4.1.84.2.0 – 4.2.33.6.12fixed from 3.6.12Metrics
Show all metrics
Weakness classes (CWE)
CWE-294Base
Authentication Bypass by Capture-replay
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-08-07 00:16 UTC· af854a3a-2127-422b-91ae-364da2661108
- Reference: http://www.openwall.com/lists/oss-security/2026/08/06/24
- Initial Analysis2026-08-06 18:41 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* versions up to (excluding) 3.6.12 *cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* versions from (including) 4.0.0 up to (excluding) 4.1.8 *cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* versions from (including) 4.2.0 up to (excluding) 4.2.3
- Reference Type: Apache Software Foundation: https://lists.apache.org/thread/6m06gdqz4rxhy9g90qz9lyqx2gqmf13o Types: Mailing List, Vendor Advisory
- CVE Modified2026-08-06 16:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- SSVC: {"id":"CVE-2026-68079","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
- New CVE Received2026-08-06 12:16 UTC· security@apache.org
- Affected: Apache CXF
- Description: In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
- CWE: CWE-294
- Reference: https://lists.apache.org/thread/6m06gdqz4rxhy9g90qz9lyqx2gqmf13o