AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-68079

CRITICAL · CVSS 9.8 EPSS 0.41%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Apache CXF is vulnerable due to a flaw in the DefaultEncryptingCodeDataProvider, allowing a captured authorization code to be reused indefinitely, which violates RFC standards. This critical vulnerability poses a significant risk of unauthorized access, potentially compromising sensitive data and user accounts. Organizations using affected versions should prioritize upgrading to versions 4.2.3, 4.1.8, or 3.6.12 to mitigate this risk.

CVE
CVE-2026-68079
Severity
CRITICAL
CVSS
9.8
EPSS
0.41%
Apache

Original NVD Description

In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)