{
  "from_raw": "Colm O hEigeartaigh <coheigea@apache.org>",
  "from": "Colm O hEigeartaigh <co...@apache.org>",
  "gravatar": "7760700ec800e9fa0453ac51f2db8802",
  "to": "an...@apache.org,\n de...@cxf.apache.org",
  "subject": "CVE-2026-50623: Apache CXF: Authentication Bypass in OAuth2 TokenIntrospectionService",
  "message-id": "<7afe06d0-fc43-e191-5510-37e22b6b1929@apache.org>",
  "mid": "fdk6t2ygpvdqfocfzt4f48nqhqdp6w9s",
  "permalinks": [
    "fdk6t2ygpvdqfocfzt4f48nqhqdp6w9s",
    "r3f70ed1f188bcda6d2adab050333cd765925bf7eb7ba02cd8a87dd08@<announce.apache.org>"
  ],
  "dbid": "f77606a62316bed6b7f6f497e8d8fc3a0170bfe73a1076a2532ff30f2d5528fe",
  "cc": "de...@cxf.apache.org",
  "epoch": 1781196596,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/06/11 16:49:56",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: moderate \n\nAffected versions:\n\n- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) 4.2.0 before 4.2.2\n- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) before 4.1.7\n\nDescription:\n\nAn authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF.\u00a0Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker. However note that this is a safeguard only in the case that someone forgot to enable authentication on the service.\u00a0Users are recommended to upgrade to version 4.2.2 or 4.1.7, which fixes this issue.\n\nCredit:\n\nGuanping Zhang reported this vulnerability. (finder)\n\nReferences:\n\nhttps://cxf.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-50623\n\n",
  "body_short": "Severity: moderate \n\nAffected versions:\n\n- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) 4.2.0 before 4.2.2\n- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) before 4.1.7\n\nDescription:\n\nA",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 2716,
  "id": "fdk6t2ygpvdqfocfzt4f48nqhqdp6w9s"
}