Improper Token Management in Apache CXF OAuth2 Authorization Code Provider
CVE-2026-73179
Currently unrated
What is CVE-2026-73179?
The vulnerability arises from the improper enforcement of single-use authorization code semantics in the JPA OAuth2 authorization code grant provider in Apache CXF. This flaw allows a remote attacker to exploit the system by obtaining multiple valid access tokens from a single authorization code through concurrent token exchange requests. The attack targets a non-atomic find-then-delete operation against a shared relational database under READ_COMMITTED isolation. It is crucial for users to upgrade to the recommended versions 4.2.4, 4.1.9, or 3.6.13 to mitigate this risk.
Affected Version(s)
Apache CXF 4.2.0 < 4.2.4
Apache CXF 4.0.0 < 4.1.9
Apache CXF 0 < 3.6.13