CVE-2026-97468 | Apache CXF up to 3.6.12/4.1.8/4.2.3 Security Token Service Cache STSTokenValidator.hashCode improper authentication

SecurityVulns

A vulnerability was found in Apache CXF up to 3.6.12/4.1.8/4.2.3. It has been rated as critical. This affects the function STSTokenValidator.hashCode of the component Security Token Service Cache. The manipulation leads to improper authentication.

This vulnerability is referenced as CVE-2026-97468. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More