CVE-2026-63687 | Apache CXF up to 3.6.11/4.1.7/4.2.2 JwtRequestCodeFilter nonce improper authentication

SecurityVulns

A vulnerability classified as critical has been found in Apache CXF up to 3.6.11/4.1.7/4.2.2. This affects the function JwtRequestCodeFilter. Performing a manipulation of the argument nonce results in improper authentication.

This vulnerability was named CVE-2026-63687. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More