CyberSec.Space Logo
Back to CVE Browser

CVE-2026-50633

HIGH
8.1
CVSS Severity Score
EPSS Score0.1070%
EPSS Percentile20.02th
PublishedJun 12, 2026
Last ModifiedJun 12, 2026

Vulnerability Description

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

Related Vulnerabilities