PT-2026-48847 · Apache+3 · Apache Cxf+7

CVE-2026-50628

·

Published

2026-06-12

·

Updated

2026-08-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description A logic error in the OAuthRequestFilter function causes legitimate requests from the bound IP address to be rejected, while requests from any other IP address are permitted. This creates an inverse security check when the security feature is enabled.
Recommendations Upgrade to versions 4.2.2 or 4.1.7.

Exploit

Fix

DoS

Improperly Implemented Security Check for Standard

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50628
GHSA-G5V7-JCHF-7JRR

Affected Products

Apache Cxf
Red Hat Fuse 7
Red Hat Jboss Enterprise Application Platform Expansion Pack
Red Hat Jboss Web Server 5
Red Hat Build Of Apache Camel 4.18.1.P1 For Spring Boot 3.5.16
Red Hat Build Of Apache Camel For Spring Boot 4
Cxf
Org.Apache.Cxf:Cxf-Rt-Rs-Security-Oauth2