What is CVE-2026-63687?
CVE-2026-63687 is a vulnerability in Apache CXF's JwtRequestCodeFilter where all claims from a signed JWT are copied to authorization parameters without filtering. A client with a validly-signed JWT can substitute security-sensitive parameters, potentially gaining unauthorized access. Affected deployments should review and update their JwtRequestCodeFilter configuration.
Azərbaycanca: CVE-2026-63687, Apache CXF-in JwtRequestCodeFilter komponentindəki zəiflikdir. İmzalanmış JWT-dəki bütün claim-lər filtrasiya edilmədən avtorizasiya parametrlərinə kopyalandığı üçün, etibarlı JWT əldə edə bilən müştəri həssas təhlükəsizlik parametrlərini dəyişdirərək icazəsiz əməliyyatlar apara bilər. Təsirə məruz qalan sistemlərdə JwtRequestCodeFilter-in konfiqurasiyası yoxlanmalı və mümkünsə yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: Apache
FAQ2
Which component of Apache CXF is affected by CVE-2026-63687?
CVE-2026-63687 is a vulnerability in the JwtRequestCodeFilter component of Apache CXF.
How can an attacker exploit CVE-2026-63687 to perform unauthorized operations?
A client with a validly-signed JWT can substitute security-sensitive parameters because all claims from the JWT are copied to authorization parameters by JwtRequestCodeFilter without filtering.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.