Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl
CVE-2026-50633

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
12 June 2026

What is CVE-2026-50633?

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

Affected Version(s)

Apache CXF 4.2.0 < 4.2.2

Apache CXF 0 < 4.1.7

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Venkatraman Kumar (r3dw0lfsec), Securin
.