CVE-2026-50631: Apache Cxf
High severity, CVSS 7.4. EPSS: 0.4% chance of exploitation in the next 30 days.
A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed concurrently by multiple attackers or threads. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
Affected products
- Apache Cxf: before 4.1.7 (fixed in 4.1.7); from 4.2.0, before 4.2.2 (fixed in 4.2.2)
Published 2026-06-12. Last modified 2026-08-07.