CyberSec.Space Logo
Back to CVE Browser

CVE-2026-50627

PENDING
N/A
CVSS Severity Score
EPSS Score0.0750%
EPSS Percentile16.74th
PublishedJun 12, 2026
Last ModifiedJun 12, 2026

Vulnerability Description

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

Related Vulnerabilities