CVE-2026-68481

CVE-2026-68481: Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider

Vendor Apache Software Foundation
Product Apache CXF
Weakness CWE-672
Published August 6, 2026
Last update August 6, 2026

CVSS base score

What the vulnerability does

01Description

In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked token MUST return {"active":false}'. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Key dates

02Disclosure timeline

August 6, 2026 CVE published
August 6, 2026 Record updated