PT-2026-48847 · Apache+3 · Apache Cxf+7
CVE-2026-50628
·
Published
2026-06-12
·
Updated
2026-08-07
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
A logic error in the
OAuthRequestFilter function causes legitimate requests from the bound IP address to be rejected, while requests from any other IP address are permitted. This creates an inverse security check when the security feature is enabled.Recommendations
Upgrade to versions 4.2.2 or 4.1.7.
Exploit
Fix
DoS
Improperly Implemented Security Check for Standard
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Cxf
Red Hat Fuse 7
Red Hat Jboss Enterprise Application Platform Expansion Pack
Red Hat Jboss Web Server 5
Red Hat Build Of Apache Camel 4.18.1.P1 For Spring Boot 3.5.16
Red Hat Build Of Apache Camel For Spring Boot 4
Cxf
Org.Apache.Cxf:Cxf-Rt-Rs-Security-Oauth2