Apache CXF Token Validation Vulnerability in OIDC Implementation
CVE-2026-65583
Currently unrated
What is CVE-2026-65583?
A vulnerability exists in Apache CXF's OpenID Connect (OIDC) implementation that allows for an authentication bypass via improper validation of self-issued ID tokens. Specifically, the relying-party token validation does not enforce essential claim checks, including issuer, subject, audience, token expiration, and sub_jwk binding. While self-issued ID tokens are not accepted by default, the flaw may still pose a risk if exploited through crafted tokens. Users are strongly advised to upgrade to updated versions 4.2.3, 4.1.8, or 3.6.12 to mitigate this issue.
Affected Version(s)
Apache CXF 4.2.0 < 4.2.3
Apache CXF 4.0.0 < 4.1.8
Apache CXF 0 < 3.6.12