Authentication Bypass Vulnerability in OidcClientCodeRequestFilter from Apache
CVE-2026-71575
Currently unrated
What is CVE-2026-71575?
A critical flaw exists in the authentication freshness check of the OidcClientCodeRequestFilter, caused by a mismatch in time unit handling and a reversed logic condition. This vulnerability allows relying parties that utilize setMaxAgeOffset for re-authentication to inadvertently accept sessions of any age, circumventing established step-up authentication protocols. It is crucial for users to upgrade to the recommended versions to secure their applications against this vulnerability.
Affected Version(s)
Apache CXF 4.2.0 < 4.2.4
Apache CXF 4.0.0 < 4.1.9
Apache CXF 0 < 3.6.13