An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. (CVE-2026-50623)
An authentication bypass vulnerability (CVE-2026-50623) exists in the OAuth2 TokenIntrospectionService of Apache CXF due to a missing 'throw' keyword in the security context check. This flaw allows unauthenticated network attackers to access the introspection endpoint if authentication is not enabled on the service. The issue is fixed in Apache CXF versions 4.2.2 and 4.1.7.
AI Analysis
Technical Summary
CVE-2026-50623 describes an authentication bypass vulnerability in the OAuth2 TokenIntrospectionService component of Apache CXF. The vulnerability arises because a missing 'throw' keyword in the security context check allows unauthenticated access to the introspection endpoint (/services/oauth2/introspect). This bypass is a safeguard failure that only applies if authentication was not properly enabled on the service. The vendor has addressed this issue in versions 4.2.2 and 4.1.7.
Potential Impact
An unauthenticated attacker can access the OAuth2 token introspection endpoint if authentication is not enabled on the service, potentially exposing token validation information. The impact is limited to cases where authentication is misconfigured or disabled, reducing the overall risk. The CVSS 3.1 base score is 6.5 (medium severity), reflecting network attack vector, low complexity, no privileges required, no user interaction, and limited confidentiality and integrity impact.
Mitigation Recommendations
Users should upgrade Apache CXF to version 4.2.2 or 4.1.7, where this vulnerability is fixed. Additionally, ensure that authentication is properly enabled on the OAuth2 TokenIntrospectionService to prevent unauthorized access. Patch status is confirmed by the vendor advisory recommending these versions.
An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. (CVE-2026-50623)
Description
An authentication bypass vulnerability (CVE-2026-50623) exists in the OAuth2 TokenIntrospectionService of Apache CXF due to a missing 'throw' keyword in the security context check. This flaw allows unauthenticated network attackers to access the introspection endpoint if authentication is not enabled on the service. The issue is fixed in Apache CXF versions 4.2.2 and 4.1.7.
CVSS v3.1
Score 6.5medium
Affected software
pkg:maven/org.apache.cxf/cxf-coreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-50623 describes an authentication bypass vulnerability in the OAuth2 TokenIntrospectionService component of Apache CXF. The vulnerability arises because a missing 'throw' keyword in the security context check allows unauthenticated access to the introspection endpoint (/services/oauth2/introspect). This bypass is a safeguard failure that only applies if authentication was not properly enabled on the service. The vendor has addressed this issue in versions 4.2.2 and 4.1.7.
Potential Impact
An unauthenticated attacker can access the OAuth2 token introspection endpoint if authentication is not enabled on the service, potentially exposing token validation information. The impact is limited to cases where authentication is misconfigured or disabled, reducing the overall risk. The CVSS 3.1 base score is 6.5 (medium severity), reflecting network attack vector, low complexity, no privileges required, no user interaction, and limited confidentiality and integrity impact.
Mitigation Recommendations
Users should upgrade Apache CXF to version 4.2.2 or 4.1.7, where this vulnerability is fixed. Additionally, ensure that authentication is properly enabled on the OAuth2 TokenIntrospectionService to prevent unauthorized access. Patch status is confirmed by the vendor advisory recommending these versions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-542g-m3fx-q86f
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-50623"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a77433fbf8831d539b47876
Added to database: 08/08/2026, 14:54:55 UTC
Last enriched: 08/08/2026, 15:43:54 UTC
Last updated: 08/08/2026, 16:02:47 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.