CVE-2026-63687

Authorization Bypass
Affects
Apache CXF
in
Apache CXF
No items found.
Versions
<3.6.12, >=4.0.0 <4.1.8, >=4.2.0 <4.2.3

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Apache CXF is an open-source services framework, maintained by the Apache Software Foundation, for building and consuming web services in Java. It implements the JAX-WS and JAX-RS APIs and supports SOAP, the WS-* standards, RESTful HTTP, and OAuth 2.0 over transports such as HTTP and JMS. Its modules are published as Maven artifacts under org.apache.cxf.

An Authorization Bypass vulnerability (CVE-2026-63687) has been identified in the JwtRequestCodeFilter of the Apache CXF OAuth 2.0 module, which allows attackers who can produce a validly signed request object JWT to replace the code_challenge, code_challenge_method, nonce, and state values sent in the outer authorization request, undermining PKCE integrity, CSRF protection, and OpenID Connect replay protection.

Per OWASP: Access control, sometimes called authorization, is how a web application grants access to content and functions to some users and not others. These checks are performed after authentication, and govern what ‘authorized’ users are allowed to do.

This issue affects versions before 3.6.12, 4.0.0 through 4.1.7, and 4.2.0 through 4.2.2 of Apache CXF.

Details

Module Info

Vulnerability Info

This Critical-severity vulnerability is found in the org.apache.cxf:cxf-rt-rs-security-oauth2 package in versions before 3.6.12, 4.0.0 through 4.1.7, and 4.2.0 through 4.2.2 of Apache CXF. CISA-ADP rates it 9.1 on CVSS v3.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Apache CXF supports the OAuth 2.0 JWT-Secured Authorization Request (JAR) pattern, in which a client passes its authorization parameters inside a signed (and optionally encrypted) request object JWT, either inline through the request parameter or by reference through request_uri. The JwtRequestCodeFilter authorization request filter verifies the JWT signature, checks the issuer, client_id, and response_type, and then merges the JWT claims into the authorization parameter map that the rest of the authorization code flow consumes.

The merge copies every claim of the JWT into the parameter map with putSingle, which replaces any value already present from the outer HTTP request. No claim is excluded, so a JWT carrying code_challenge, code_challenge_method, nonce, or state silently overrides the values the outer request supplied:

MultivaluedMap<String, String> newParams = new MetadataMap<>(params);
Map<String, Object> claimsMap = claims.asMap();
for (Map.Entry<String, Object> entry : claimsMap.entrySet()) {
    String key = entry.getKey();
    Object value = entry.getValue();
    if (value instanceof Map) {
        Map<String, Object> map = CastUtils.cast((Map<?, ?>)value);
        value = jsonHandler.toJson(map);
    } else if (value instanceof List) {
        List<Object> list = CastUtils.cast((List<?>)value);
        value = jsonHandler.toJson(list);
    }
    newParams.putSingle(key, value.toString());
}
return newParams;

The outer request's PKCE, state, and nonce values bind the authorization flow to the legitimate client's session, so a request object should never be able to replace them. Because CXF lets the JWT win, anyone able to produce a validly signed request object for a client can substitute their own PKCE code_challenge and code_challenge_method, which breaks the binding between the authorization code and the legitimate client's code_verifier and enables authorization code interception and injection. The same override lets the attacker replace state, defeating the client's CSRF protection, and nonce, defeating OpenID Connect ID token replay protection.

This vulnerability was introduced in 2014 with Apache CXF 3.0.3.

Mitigation

Only recent versions of Apache CXF are community-supported. The 3.5.x line was already End-of-Life when this CVE was published and will not receive public updates to address this issue.

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Apache CXF release line (3.6.x or later) that contains the fix.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support.

Credits

  • Guanping Zhang (finder)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Critical
ID
CVE-2026-63687
PROJECT Affected
Apache CXF
Versions Affected
<3.6.12, >=4.0.0 <4.1.8, >=4.2.0 <4.2.3
NES Versions Affected
Published date
September 26, 2026
≈ Fix date
September 29, 2026
Category
Authorization Bypass
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Apache CXF
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.