Improper Token Management in Apache CXF OAuth2 Authorization Code Provider
CVE-2026-73179

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
9 October 2026

What is CVE-2026-73179?

The vulnerability arises from the improper enforcement of single-use authorization code semantics in the JPA OAuth2 authorization code grant provider in Apache CXF. This flaw allows a remote attacker to exploit the system by obtaining multiple valid access tokens from a single authorization code through concurrent token exchange requests. The attack targets a non-atomic find-then-delete operation against a shared relational database under READ_COMMITTED isolation. It is crucial for users to upgrade to the recommended versions 4.2.4, 4.1.9, or 3.6.13 to mitigate this risk.

Affected Version(s)

Apache CXF 4.2.0 < 4.2.4

Apache CXF 4.0.0 < 4.1.9

Apache CXF 0 < 3.6.13

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Guanping Zhang reported this vulnerability
.