Vulnerability Description
In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked token MUST return {"active":false}'. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Cxf | < 3.6.12 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/88c0h10yjb2b8201o1km3st71fs2zw2bMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/08/06/25
FAQ
What is CVE-2026-68481?
CVE-2026-68481 is a vulnerability with a CVSS score of 7.5 (HIGH). In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violat...
How severe is CVE-2026-68481?
CVE-2026-68481 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-68481?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Cxf.