What is CVE-2026-68481?
In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access and refresh tokens still decrypt successfully, and the TokenIntrospectionService incorrectly reports them as active (`active:true`). This violates RFC stipulations requiring token invalidation upon revocation, potentially allowing unauthorized access using revoked tokens. Affected systems must urgently apply the vendor-provided patch.
Azərbaycanca: Bu CVE Apache CXF-in DefaultEncryptingOAuthDataProvider komponentində revoke edilmiş giriş tokenlərinin (`access token` və `refresh token`) uğurla şifrədən çıxarılmasına (decrypt) və TokenIntrospectionService tərəfindən aktiv (`active:true`) kimi göstərilməsinə səbəb olan boşluqdur. RFC standartlarına zidd olaraq, ləğv (invalidate) əməliyyatı düzgün icra olunmadığı üçün, zərərli şəxslər revoke edilmiş tokenlərdən istifadə edərək resurslara icazəsiz giriş əldə edə bilər. Bu zəiflikdən təsirlənən sistemlərdə təcili olaraq Apache CXF yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: shared vendor: Apache
FAQ2
Which component in Apache CXF is affected by CVE-2026-68481?
This CVE affects the DefaultEncryptingOAuthDataProvider component.
What can be achieved with revoked tokens by exploiting CVE-2026-68481?
Revoked access and refresh tokens still decrypt successfully, and the TokenIntrospectionService reports them as active (`active:true`), potentially allowing unauthorized access to resources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.