CVE-2026-49875: CWE-611 Improper Restriction of XML External Entity Reference in Apache Software Foundation Apache CXF
CVE-2026-49875 is an information disclosure vulnerability in Apache CXF caused by improper XML parser configuration that allows out-of-band external entity resolution. This flaw affects the EndpointReferenceUtils and W3CMultiSchemaFactory classes, enabling remote attackers to disclose sensitive information without user interaction. The vulnerability is addressed in Apache CXF versions 4.2.2, 4.1.7, and 3.6.12. Red Hat products bundling Apache CXF are also affected, but currently no effective mitigation or fix meeting Red Hat's criteria is available for those products.
AI Analysis
Technical Summary
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without applying necessary JAXP hardening configurations, resulting in an XML External Entity (XXE) vulnerability (CWE-611). This allows out-of-band external entity resolution, which can be exploited by remote attackers to disclose sensitive information from the affected system. The vulnerability affects multiple Apache CXF versions prior to 4.1.7 and 4.2.2. Red Hat advisories confirm the issue affects their products that bundle Apache CXF, such as Enterprise Application Platform and JBoss Web Server. No mitigation or fix currently meets Red Hat's criteria for ease of deployment and applicability, though Apache CXF upstream versions 4.2.2, 4.1.7, and 3.6.12 include fixes.
Potential Impact
The vulnerability allows remote attackers to disclose sensitive information by exploiting improper XML parsing configurations that enable out-of-band external entity resolution. This can lead to reading arbitrary files on the system or causing the application to make unintended network requests. The impact is confidentiality loss without integrity or availability impact. Red Hat products bundling Apache CXF are affected, but no fix or mitigation currently meets their criteria. The CVSS 3.1 base score is 6.5 (medium severity) reflecting high confidentiality impact with low attack complexity and no user interaction required.
Mitigation Recommendations
Upgrading Apache CXF to versions 4.2.2, 4.1.7, or 3.6.12 is recommended to address this vulnerability. For Red Hat products bundling Apache CXF, no mitigation or fix currently meets Red Hat's criteria for deployment and stability. Users should monitor Red Hat advisories for updates and consider upgrading to fixed versions when available. No vendor-provided temporary fixes or workarounds are currently documented.
CVE-2026-49875: CWE-611 Improper Restriction of XML External Entity Reference in Apache Software Foundation Apache CXF
Description
CVE-2026-49875 is an information disclosure vulnerability in Apache CXF caused by improper XML parser configuration that allows out-of-band external entity resolution. This flaw affects the EndpointReferenceUtils and W3CMultiSchemaFactory classes, enabling remote attackers to disclose sensitive information without user interaction. The vulnerability is addressed in Apache CXF versions 4.2.2, 4.1.7, and 3.6.12. Red Hat products bundling Apache CXF are also affected, but currently no effective mitigation or fix meeting Red Hat's criteria is available for those products.
CVSS v3.1
Score 6.5medium
Affected software
Apache Software Foundation
Apache CXF
pkg:maven/Apache Software Foundation/org.apache.cxf:cxf-coreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without applying necessary JAXP hardening configurations, resulting in an XML External Entity (XXE) vulnerability (CWE-611). This allows out-of-band external entity resolution, which can be exploited by remote attackers to disclose sensitive information from the affected system. The vulnerability affects multiple Apache CXF versions prior to 4.1.7 and 4.2.2. Red Hat advisories confirm the issue affects their products that bundle Apache CXF, such as Enterprise Application Platform and JBoss Web Server. No mitigation or fix currently meets Red Hat's criteria for ease of deployment and applicability, though Apache CXF upstream versions 4.2.2, 4.1.7, and 3.6.12 include fixes.
Potential Impact
The vulnerability allows remote attackers to disclose sensitive information by exploiting improper XML parsing configurations that enable out-of-band external entity resolution. This can lead to reading arbitrary files on the system or causing the application to make unintended network requests. The impact is confidentiality loss without integrity or availability impact. Red Hat products bundling Apache CXF are affected, but no fix or mitigation currently meets their criteria. The CVSS 3.1 base score is 6.5 (medium severity) reflecting high confidentiality impact with low attack complexity and no user interaction required.
Mitigation Recommendations
Upgrading Apache CXF to versions 4.2.2, 4.1.7, or 3.6.12 is recommended to address this vulnerability. For Red Hat products bundling Apache CXF, no mitigation or fix currently meets Red Hat's criteria for deployment and stability. Users should monitor Red Hat advisories for updates and consider upgrading to fixed versions when available. No vendor-provided temporary fixes or workarounds are currently documented.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-06-02T08:45:53.536Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-49875","vendor":"Red Hat"}]
Threat ID: 6a2bd75be617e2d83448bfa6
Added to database: 06/12/2026, 09:54:35 UTC
Last enriched: 08/14/2026, 16:23:03 UTC
Last updated: 09/12/2026, 22:01:34 UTC
Views: 83
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.