CVE-2026-57818

CVE-2026-57818: Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider

Vendor Apache Software Foundation
Product Apache CXF
Weakness CWE-367
Published August 6, 2026
Last update August 6, 2026

CVSS base score

What the vulnerability does

01Description

A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue.

Key dates

02Disclosure timeline

August 6, 2026 CVE published