CVE-2026-65583 Details
Description
Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fixes this issue.
An authentication bypass vulnerability has been identified in Apache CXF's OpenID Connect (OIDC) relying-party token validation. This issue arises because the validation process could accept self-issued ID tokens without applying the necessary claim checks, such as issuer, subject, audience, time, and sub_jwk binding. Although self-issued ID tokens are not accepted by default, the lack of enforcement on these claims could allow crafted tokens to bypass authentication. The vulnerability affects Apache CXF versions 4.2.0 prior to 4.2.3, 4.0.0 prior to 4.1.8, and versions prior to 3.6.12.
Users are advised to upgrade to Apache CXF versions 4.2.3, 4.1.8, or 3.6.12, all of which address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/08/06/23 | CVE | |
| https://lists.apache.org/thread/fzj8yzgfl53gclxrcdrnrx3grcpkq51j | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache cxf | < 3.6.12 >= 4.0.0, < 4.1.8 >= 4.2.0, < 4.2.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | CVE Modified | CVE |
| Aug 6, 2026 | Initial Analysis | [email protected] |
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |