CVE-2026-50628
Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 9.8EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
12 jun 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this
security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Apache Software Foundation · Apache CXFReferencias
https://access.redhat.com/security/cve/CVE-2026-50628https://bugzilla.redhat.com/show_bug.cgi?id=2488302https://lists.apache.org/thread/vb3ho8lf228gh90m1fpnohf2008xrdxkhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50628.jsonhttp://www.openwall.com/lists/oss-security/2026/06/11/5