What is CVE-2026-68079?
CVE-2026-68079 in Apache CXF's DefaultEncryptingCodeDataProvider allows a captured authorization code to be redeemed an unlimited number of times due to a flaw in the removeCodeGrant function. This violates the RFC requirement that an authorization code must not be used more than once, primarily affecting applications using Apache CXF. Immediate update of the affected component to the latest version is recommended.
Azərbaycanca: Apache CXF-də aşkarlanan CVE-2026-68079, DefaultEncryptingCodeDataProvider komponentində removeCodeGrant funksiyasındakı qüsur səbəbindən ələ keçirilmiş authorization code-un limitsiz sayda istifadəsinə imkan verir. Bu, RFC standartının pozulmasıdır və əsasən Apache CXF istifadə edən tətbiqlərə təsir göstərir. Dərhal bu komponenti ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: Apache
FAQ2
What does the CVE-2026-68079 vulnerability in Apache CXF involve?
This vulnerability involves a flaw in the removeCodeGrant function within the DefaultEncryptingCodeDataProvider component, allowing a captured authorization code to be redeemed an unlimited number of times.
What measure should be taken to protect against CVE-2026-68079?
It is recommended to immediately update the affected Apache CXF component to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.