imPC@ndo IT

Tracker / CVE-2026-68079

CVE-2026-68079

Critical 9.8

In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Affected products and versions

apache cxf · … → 3.6.12
apache cxf · 4.0.0 → 4.1.8
apache cxf · 4.2.0 → 4.2.3

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References