CVE-2026-50628
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Apache CXF is an open-source services framework, maintained by the Apache Software Foundation, for building and consuming web services in Java. It implements the JAX-WS and JAX-RS APIs and supports SOAP, the WS-* standards, RESTful HTTP, and OAuth 2.0 over transports such as HTTP and JMS. Its modules are published as Maven artifacts under org.apache.cxf.
An Authorization Bypass vulnerability (CVE-2026-50628) has been identified in the OAuth 2.0 access token filter (OAuthRequestFilter) of the cxf-rt-rs-security-oauth2 module, which allows attackers to use an IP-bound OAuth 2.0 access token from any network address other than the one it is bound to, while requests from the legitimate bound address are rejected.
Per OWASP: Access control enforces policy such that users cannot act outside of their intended permissions. Failures typically lead to unauthorized information disclosure, modification, or destruction of all data or performing a business function outside the user's limits.
This issue affects the cxf-rt-rs-security-oauth2 module in versions 3.0.4 before 3.6.12, 4.0.0 before 4.1.7, and 4.2.0 before 4.2.2 of Apache CXF.
Details
Module Info
- Product: Apache CXF
- Affected packages:
org.apache.cxf:cxf-rt-rs-security-oauth2 - Affected versions: <3.6.12, >=4.0.0 <4.1.7, >=4.2.0 <4.2.2
- GitHub repository: https://github.com/apache/cxf
- Published packages: https://central.sonatype.com/artifact/org.apache.cxf/cxf-rt-rs-security-oauth2
- Package manager: Maven
- Fixed in:
- OSS Apache CXF 3.6.12, 4.1.7, 4.2.2
- NES for Apache CXF v3.5.13, v3.4.12
Vulnerability Info
This Critical-severity vulnerability is found in the org.apache.cxf:cxf-rt-rs-security-oauth2 package in versions <3.6.12, >=4.0.0 <4.1.7, and >=4.2.0 <4.2.2 of Apache CXF.
An authorization server can bind an OAuth 2.0 access token to the IP address of the client it was issued to. When a protected JAX-RS resource receives a bearer token, OAuthRequestFilter validates it and then enforces that binding by comparing the bound address with the remote address of the incoming HTTP request. In the affected versions the comparison is inverted: the filter returns 403 Forbidden when the request comes from the bound address, and lets the request through when it comes from any other address.
if (accessTokenV.getClientIpAddress() != null) {
String remoteAddress = getMessageContext().getHttpServletRequest().getRemoteAddr();
if (remoteAddress == null || accessTokenV.getClientIpAddress().equals(remoteAddress)) {
String message = "Client IP Address is invalid";
LOG.warning(message);
throw ExceptionUtils.toForbiddenException(null, null);
}
}
As a result, the IP binding does not protect anything. If an IP-bound access token is stolen or leaked, an attacker can replay it from their own machine and the filter accepts it. The legitimate client, calling from the bound address, is refused. The attacker needs no authentication beyond holding the token, and the attack works over the network against any endpoint protected by OAuthRequestFilter where tokens carry a client IP address.
Mitigation
Only recent versions of Apache CXF receive community support. Older lines are End-of-Life and will not receive public updates to address this issue.
Users of the affected components should apply one of the following mitigations:
- Upgrade to a currently supported Apache CXF release line (3.6.x or later) that contains the fix.
- Leverage a commercial support partner like HeroDevs for post-EOL security support.
Credits
- Guanping Zhang (finder)