No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 08 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-303 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 06 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 06 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache cxf |
|
| Vendors & Products |
Apache
Apache cxf |
Thu, 06 Aug 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked token MUST return {"active":false}'. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue. | |
| Title | Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider | |
| Weaknesses | CWE-672 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-08-07T00:01:55.439Z
Reserved: 2026-07-30T09:30:48.213Z
Link: CVE-2026-68481
Updated: 2026-08-07T00:01:55.439Z
No data.
OpenCVE Enrichment
Updated: 2026-08-08T02:00:13Z