CVE-2026-61466

Summary

In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the scope value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache CXF0 < 3.6.12affected
Apache Software FoundationApache CXF4.0.0 < 4.1.8affected
Apache Software FoundationApache CXF4.2.0 < 4.2.3affected

Weaknesses

  • CWE-304: CWE-304 Missing Critical Step in Authentication

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

CVE Program Container

Additional References

References