AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-68481

HIGH · CVSS 7.5 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Apache CXF's DefaultEncryptingOAuthDataProvider is vulnerable as it allows revoked access and refresh tokens to still decrypt successfully, falsely reporting them as active. This non-compliance with RFC standards poses a significant security risk, as it undermines token invalidation processes. Organizations using affected versions should prioritize upgrading to 4.2.3, 4.1.8, or 3.6.12 to mitigate potential unauthorized access.

CVE
CVE-2026-68481
Severity
HIGH
CVSS
7.5
EPSS
0.43%
Apache

Original NVD Description

In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked token MUST return {"active":false}'. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)