Vulnerability Description
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Cxf | < 4.1.7 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/1czhgovkgzdkyp3t61wthn0foogh2grfVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/06/11/10Mailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:37390
- https://access.redhat.com/security/cve/CVE-2026-50633
- https://bugzilla.redhat.com/show_bug.cgi?id=2488307
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50633.json
FAQ
What is CVE-2026-50633?
CVE-2026-50633 is a vulnerability with a CVSS score of 8.1 (HIGH). A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xm...
How severe is CVE-2026-50633?
CVE-2026-50633 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-50633?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Cxf.