CVE-2026-50623 | Apache CXF up to 4.1.6/4.2.1 OAuth2 TokentrospectionService improper authentication
A vulnerability labeled as critical has been found in Apache CXF up to 4.1.6/4.2.1. The affected element is the function TokentrospectionService of the component OAuth2. The manipulation results in improper authentication.
This vulnerability is cataloged as CVE-2026-50623. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More