AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-57817

HIGH · CVSS 8.1 EPSS 0.44%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Apache CXF implementations that utilize the Hybrid Flow of the OpenID Connect Core 1.0 specification are vulnerable if integrated with non-compliant or misconfigured Identity Providers that do not validate the `c_hash` parameter. This vulnerability can lead to Authorization Code Substitution/Injection attacks, potentially compromising user authentication and authorization processes. Organizations using affected versions should prioritize upgrading to at least versions 4.2.3, 4.1.8, or 3.6.12 to mitigate this risk.

CVE
CVE-2026-57817
Severity
HIGH
CVSS
8.1
EPSS
0.44%
Apache

Original NVD Description

The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)