CVE-2026-65583

CVE-2026-65583: Apache CXF: Self-issued ID token claims validation skipped

Vendor Apache Software Foundation
Product Apache CXF
Weakness CWE-345
Published August 6, 2026
Last update August 6, 2026

CVSS base score

What the vulnerability does

01Description

Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fixes this issue.

Key dates

02Disclosure timeline

August 6, 2026 CVE published
August 6, 2026 Record updated

Related vulnerabilities

04Related CVE