Apache CXF OAuth2 Client Reg: Unvalidated Scope Self-Assignment (4.2.3)
CVE-2026-61466 Published on August 6, 2026

Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Vendor Advisory NVD

Weakness Type

Missing Critical Step in Authentication

The software implements an authentication technique, but it skips a step that weakens the technique. Authentication techniques should follow the algorithms that define them exactly, otherwise authentication can be bypassed or more easily subjected to brute force attacks.


Products Associated with CVE-2026-61466

Want to know whenever a new CVE is published for Apache CXF? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache CXF: