CVE-2026-50628

Authorization Bypass
Affects
Apache CXF
in
Apache CXF
No items found.
Versions
<3.6.12, >=4.0.0 <4.1.7, >=4.2.0 <4.2.2

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Apache CXF is an open-source services framework, maintained by the Apache Software Foundation, for building and consuming web services in Java. It implements the JAX-WS and JAX-RS APIs and supports SOAP, the WS-* standards, RESTful HTTP, and OAuth 2.0 over transports such as HTTP and JMS. Its modules are published as Maven artifacts under org.apache.cxf.

An Authorization Bypass vulnerability (CVE-2026-50628) has been identified in the OAuth 2.0 access token filter (OAuthRequestFilter) of the cxf-rt-rs-security-oauth2 module, which allows attackers to use an IP-bound OAuth 2.0 access token from any network address other than the one it is bound to, while requests from the legitimate bound address are rejected.

Per OWASP: Access control enforces policy such that users cannot act outside of their intended permissions. Failures typically lead to unauthorized information disclosure, modification, or destruction of all data or performing a business function outside the user's limits.

This issue affects the cxf-rt-rs-security-oauth2 module in versions 3.0.4 before 3.6.12, 4.0.0 before 4.1.7, and 4.2.0 before 4.2.2 of Apache CXF.

Details

Module Info

Vulnerability Info

This Critical-severity vulnerability is found in the org.apache.cxf:cxf-rt-rs-security-oauth2 package in versions <3.6.12, >=4.0.0 <4.1.7, and >=4.2.0 <4.2.2 of Apache CXF.

An authorization server can bind an OAuth 2.0 access token to the IP address of the client it was issued to. When a protected JAX-RS resource receives a bearer token, OAuthRequestFilter validates it and then enforces that binding by comparing the bound address with the remote address of the incoming HTTP request. In the affected versions the comparison is inverted: the filter returns 403 Forbidden when the request comes from the bound address, and lets the request through when it comes from any other address.

if (accessTokenV.getClientIpAddress() != null) {
    String remoteAddress = getMessageContext().getHttpServletRequest().getRemoteAddr();
    if (remoteAddress == null || accessTokenV.getClientIpAddress().equals(remoteAddress)) {
        String message = "Client IP Address is invalid";
        LOG.warning(message);
        throw ExceptionUtils.toForbiddenException(null, null);
    }
}

As a result, the IP binding does not protect anything. If an IP-bound access token is stolen or leaked, an attacker can replay it from their own machine and the filter accepts it. The legitimate client, calling from the bound address, is refused. The attacker needs no authentication beyond holding the token, and the attack works over the network against any endpoint protected by OAuthRequestFilter where tokens carry a client IP address.

Mitigation

Only recent versions of Apache CXF receive community support. Older lines are End-of-Life and will not receive public updates to address this issue.

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Apache CXF release line (3.6.x or later) that contains the fix.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support.

Credits

  • Guanping Zhang (finder)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Critical
ID
CVE-2026-50628
PROJECT Affected
Apache CXF
Versions Affected
<3.6.12, >=4.0.0 <4.1.7, >=4.2.0 <4.2.2
NES Versions Affected
Published date
September 26, 2026
≈ Fix date
September 29, 2026
Category
Authorization Bypass
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Apache CXF
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.