Token Cache Vulnerability in Apache CXF Security Token Service
CVE-2026-97468

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
9 October 2026

What is CVE-2026-97468?

The Apache CXF implementation of Security Token Service (STS) suffers from a vulnerability that allows an attacker to forge security tokens due to the inadequate caching mechanism based on a non-cryptographic hash. This allows malicious actors to exploit cache hits as proof of valid authentication without proper validation steps. If an attacker creates a token that generates the same hash as a legitimate cached token, they can bypass password checks, signature verification, and effectively impersonate other users. To mitigate this vulnerability, it is crucial for users to upgrade to the latest versions of Apache CXF.

Affected Version(s)

Apache CXF 4.2.0 < 4.2.4

Apache CXF 4.0.0 < 4.1.9

Apache CXF 0 < 3.6.13

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MopMonk-AI
.