CVE-2026-61466

CVE-2026-61466: Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation

Vendor Apache Software Foundation
Product Apache CXF
Weakness CWE-304
Published August 6, 2026
Last update August 6, 2026

CVSS base score

What the vulnerability does

01Description

In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Key dates

02Disclosure timeline

August 6, 2026 CVE published
August 6, 2026 Record updated