CVE-2026-61466

CVE-2026-61466 is a critical-severity vulnerability in Apache Cxf with a CVSS 3.x base score of 9.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-304.

Key facts

Description

In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Frequently asked questions

What is CVE-2026-61466?
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
How severe is CVE-2026-61466?
CVE-2026-61466 has a CVSS 3.x base score of 9.1, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability high.
Is CVE-2026-61466 being actively exploited?
It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (37th percentile), an estimate of the probability of exploitation in the next 30 days.
What products are affected by CVE-2026-61466?
CVE-2026-61466 affects Apache Cxf. See the affected-products list for the exact vulnerable versions.
How do I fix CVE-2026-61466?
Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
When was CVE-2026-61466 published?
CVE-2026-61466 was published on 2026-08-06 and last updated on 2026-08-07.

References

Affected products (1)

More vulnerabilities in Apache Cxf

All CVEs affecting Apache Cxf →

Other CWE-304 vulnerabilities

Browse all CWE-304 vulnerabilities →