Skip to main content
EPSS 0.9%top 44%

CVE-2026-50633: CWE-20 Improper Input Validation in Apache Software Foundation Apache CXF

0
High
Published: 06/12/2026 (06/12/2026, 09:02:02 UTC)
Source: CVE Database V5
Vendor/Project: Apache Software Foundation
Product: Apache CXF

Description

CVE-2026-50633 is a high-severity JNDI Injection vulnerability in Apache CXF's JCA integration module that allows arbitrary code execution if an attacker can manipulate the JCA deployment descriptor or runtime activation parameters. The vulnerability affects multiple versions of Apache CXF prior to 4.1.7, 4.2.2, and 3.6.12. The attack complexity is high, requiring specific conditions for exploitation. Red Hat products shipping Apache CXF are affected, but no effective mitigation is currently available that meets Red Hat's criteria. Users are recommended to upgrade to fixed versions to remediate the issue.

CVSS v3.1

Score 8.1high

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected software

Apache Software Foundation

Apache CXF

Affected versions
>=4.2.0 <4.2.2>=4.0.0 <4.1.7>=0 <3.6.12
Apache Software Foundation/org.apache.cxf:cxf-integration-jca
pkg:maven/Apache Software Foundation/org.apache.cxf:cxf-integration-jca
Affected versions
>=4.2.0 <4.2.2>=4.0.0 <4.1.7>=0 <3.6.12

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 16:24:11 UTC

Technical Analysis

This vulnerability in Apache CXF's JCA integration module (CVE-2026-50633) is a JNDI Injection flaw that enables remote attackers to execute arbitrary code by manipulating the Java EE Connector Architecture (JCA) deployment descriptor (ra.xml) or runtime activation parameters. The flaw is categorized under CWE-20 (Improper Input Validation) and CWE-502 (Deserialization of Untrusted Data). The vulnerability has a CVSS v3.1 score of 8.1 (High) with network attack vector, high attack complexity, no privileges required, and no user interaction. Red Hat's advisory confirms the vulnerability affects their products such as JBoss Fuse and Red Hat build of Apache Camel. No effective mitigation is currently available aside from upgrading to fixed versions 4.2.2, 4.1.7, or 3.6.12. The vulnerability can lead to full confidentiality, integrity, and availability impact through arbitrary code execution.

Potential Impact

Successful exploitation allows remote attackers to execute arbitrary code on affected systems by injecting malicious JNDI references via manipulated JCA deployment descriptors or runtime parameters. This results in complete compromise of confidentiality, integrity, and availability. The attack complexity is high, indicating that exploitation requires specific conditions. There are no known exploits in the wild at this time. The vulnerability affects Red Hat products shipping Apache CXF, including JBoss Fuse and Red Hat build of Apache Camel.

Mitigation Recommendations

Red Hat advisories indicate that no effective mitigation currently meets their criteria for ease of use, applicability, or stability. The recommended remediation is to upgrade affected Apache CXF versions to 4.2.2, 4.1.7, or 3.6.12 where the vulnerability is fixed. Users should apply these updates as soon as possible. Monitor vendor advisories for any future mitigation options or patches. No other mitigations are currently advised by the vendor.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
apache
Date Reserved
2026-06-05T11:16:38.629Z
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-50633","vendor":"Red Hat"}]

Threat ID: 6a2bd75fe617e2d83448c001

Added to database: 06/12/2026, 09:54:39 UTC

Last enriched: 08/14/2026, 16:24:11 UTC

Last updated: 09/14/2026, 10:01:31 UTC

Views: 224

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses