Authentication Bypass Vulnerability in OidcClientCodeRequestFilter from Apache
CVE-2026-71575

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
9 October 2026

What is CVE-2026-71575?

A critical flaw exists in the authentication freshness check of the OidcClientCodeRequestFilter, caused by a mismatch in time unit handling and a reversed logic condition. This vulnerability allows relying parties that utilize setMaxAgeOffset for re-authentication to inadvertently accept sessions of any age, circumventing established step-up authentication protocols. It is crucial for users to upgrade to the recommended versions to secure their applications against this vulnerability.

Affected Version(s)

Apache CXF 4.2.0 < 4.2.4

Apache CXF 4.0.0 < 4.1.9

Apache CXF 0 < 3.6.13

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Guanping Zhang reported this vulnerability
.