Apache CXF: Revoked Tokens Introspected Successfully (CVE-2026-68481)
CVE-2026-68481 Published on August 6, 2026

Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked token MUST return {"active":false}'. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Vendor Advisory NVD

Weakness Type

Operation on a Resource after Expiration or Release

The software uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.


Products Associated with CVE-2026-68481

Want to know whenever a new CVE is published for Apache CXF? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache CXF: