CVE-2026-61466

Authorization Bypass
Affects
Apache CXF
in
Apache CXF
No items found.
Versions
>=3.1.8 <3.6.12, >=4.0.0 <4.1.8, >=4.2.0 <4.2.3

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Apache CXF is an open-source services framework, maintained by the Apache Software Foundation, for building and consuming web services in Java. It implements the JAX-WS and JAX-RS APIs and supports SOAP, the WS-* standards, RESTful HTTP, and OAuth 2.0 over transports such as HTTP and JMS. Its modules are published as Maven artifacts under org.apache.cxf.

An Authorization Bypass vulnerability (CVE-2026-61466) has been identified in the OAuth 2.0 Dynamic Client Registration endpoint (DynamicRegistrationService) of the cxf-rt-rs-security-oauth2 module, which allows attackers to register a client with privileged scopes that the authorization server never intended to grant, and then obtain access tokens carrying those scopes.

Per OWASP: Access control enforces policy such that users cannot act outside of their intended permissions. Failures typically lead to unauthorized information disclosure, modification, or destruction of all data or performing a business function outside the user's limits.

This issue affects versions 3.1.8 up to but not including 3.6.12, versions 4.0.0 up to but not including 4.1.8, and versions 4.2.0 up to but not including 4.2.3 of Apache CXF.

Details

Module Info

Vulnerability Info

This Critical-severity vulnerability is found in the org.apache.cxf:cxf-rt-rs-security-oauth2 package in versions 3.1.8 up to but not including 3.6.12, versions 4.0.0 up to but not including 4.1.8, and versions 4.2.0 up to but not including 4.2.3 of Apache CXF.

Apache CXF ships a JAX-RS implementation of OAuth 2.0 Dynamic Client Registration (RFC 7591), exposed at the register path by DynamicRegistrationService. A client POSTs a JSON registration document, and createNewClient builds the new Client from its metadata. The optional scope member of that document is parsed and stored directly as the client's registered scopes:

// Client Scopes
String scope = request.getScope();
if (!StringUtils.isEmpty(scope)) {
    client.setRegisteredScopes(OAuthUtils.parseScope(scope));
}

No check compares the requested values against the scopes the authorization server is willing to hand out, such as the permissions configured on the OAuth data provider. The registered scopes are what CXF's grant handlers later use to decide which scopes the client may request. As a result, whoever can reach the registration endpoint can register a client that lists any scope, including administrative or otherwise privileged ones, and then request access tokens for those scopes (for example through the client credentials grant). Resource servers that rely on token scopes for authorization will then accept the attacker's tokens for operations the client was never meant to perform.

The registration endpoint only requires an initial access token when initialAccessToken is configured. Deployments that leave it open, or that hand out initial access tokens to less trusted parties, let those parties escalate their clients' scopes.

This vulnerability was introduced in 2016 with Apache CXF 3.1.8.

Mitigation

The 3.5.x line was already End-of-Life when this CVE was published and will not receive public updates to address this issue.

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Apache CXF release line (3.6.x or later) that contains the fix.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support.

Credits

  • Guanping Zhang (finder)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Critical
ID
CVE-2026-61466
PROJECT Affected
Apache CXF
Versions Affected
>=3.1.8 <3.6.12, >=4.0.0 <4.1.8, >=4.2.0 <4.2.3
NES Versions Affected
Published date
October 1, 2026
≈ Fix date
September 29, 2026
Category
Authorization Bypass
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Apache CXF
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.