CVE-2026-50628
Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
12 Jun 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this
security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Apache Software Foundation · Apache CXFReferences
https://access.redhat.com/security/cve/CVE-2026-50628https://bugzilla.redhat.com/show_bug.cgi?id=2488302https://lists.apache.org/thread/vb3ho8lf228gh90m1fpnohf2008xrdxkhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50628.jsonhttp://www.openwall.com/lists/oss-security/2026/06/11/5