What is CVE-2026-65583?
This vulnerability in Apache CXF's OIDC relying-party token validation allows attackers to bypass authentication using crafted self-issued ID tokens without enforcing required checks for issuer, subject, audience, time, and sub_jwk binding. Affected systems should immediately update Apache CXF and ensure OIDC configurations reject self-issued tokens.
Azərbaycanca: Bu zəiflik Apache CXF-in OIDC relying-party token təsdiqləmə mexanizmində aşkar edilib. Təcavüzkar xüsusi hazırlanmış self-issued ID token vasitəsilə issuer, subject, audience, zaman və sub_jwk bağlaması kimi vacib yoxlamalardan yan keçərək autentifikasiyanı bypass edə bilər. Təsirə məruz qalan sistemlərdə dərhal Apache CXF yenilənməsi tətbiq edilməli və OIDC konfiqurasiyasında self-issued token-lərin qəbul edilməməsi təmin olunmalıdır.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Apache
FAQ2
Which mechanism in Apache CXF is affected by CVE-2026-65583?
This vulnerability affects Apache CXF's OIDC relying-party token validation mechanism.
How can an attacker bypass authentication using this vulnerability?
An attacker can bypass authentication by using crafted self-issued ID tokens without enforcing required checks for issuer, subject, audience, time, and sub_jwk binding.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.