What is CVE-2026-61466?
A vulnerability in Apache CXF's OAuth2 Dynamic Client Registration endpoint where the `scope` parameter is accepted without validation against an allowlist. This flaw allows a client to self-assign privileged scopes during registration, potentially leading to unauthorized actions. Affected server administrators should promptly apply the necessary patches.
Azərbaycanca: Apache CXF-in OAuth2 Dynamic Client Registration mexanizmində `scope` parametrlərinin düzgün yoxlanılmaması zəifliyidir. Bu, müştəriyə qeydiyyat zamanı özünə yüksək imtiyazlı `scope`lar təyin etməyə imkan verir, nəticədə icazəsiz əməliyyatlar həyata keçirilə bilər. Təsirə məruz qalan serverlərin administratorları dərhal müvafiq yamaqları tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Apache
FAQ2
Which mechanism in Apache CXF is affected by CVE-2026-61466?
The vulnerability exists in Apache CXF's OAuth2 Dynamic Client Registration mechanism.
What is the root cause of CVE-2026-61466?
The `scope` parameter is not validated against an allowlist during client registration.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.