Token Introspection Flaw in Apache CXF Affects Security Validation
CVE-2026-68481
Currently unrated
What is CVE-2026-68481?
A security vulnerability exists in Apache CXF's DefaultEncryptingOAuthDataProvider, where revoked tokens can still be decrypted successfully. This leads to a situation where the TokenIntrospectionService incorrectly reports revoked tokens as active, contravening established RFC standards that dictate that revoked tokens must be rendered inactive. To mitigate this flaw, users should upgrade to Apache CXF versions 4.2.3, 4.1.8, or 3.6.12 that contain fixes addressing this oversight.
Affected Version(s)
Apache CXF 4.2.0 < 4.2.3
Apache CXF 4.0.0 < 4.1.8
Apache CXF 0 < 3.6.12