CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2026-50627

PENDING
N/A
CVSS Severity Score
EPSS Score0.0750%
EPSS Percentile16.74th
Published2026年6月12日
Last Modified2026年6月12日

Vulnerability Description

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

相關漏洞威脅