Apache CXF < 3.6.12 / 4.x < 4.1.8 / 4.2.x < 4.2.3 Multiple Vulnerabilities

critical Nessus Plugin ID 335183

Synopsis

Apache CXF is affected by multiple vulnerabilities.

Description

The version of Apache CXF installed on the remote host is prior to 3.6.12, or 4.x prior to 4.1.8, or 4.2.x prior to 4.2.3. It is, therefore, affected by multiple vulnerabilities, including:

- The JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. An attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or remote code execution. (CVE-2026-66909)

- In DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality, violating the RFC requirement that the authorization code must not be used more than once. (CVE-2026-68079)

- The OAuth2 Dynamic Client Registration endpoint accepts and stores the scope value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. (CVE-2026-61466)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Apache CXF version 3.6.12, 4.1.8, or 4.2.3 or later.

See Also

https://lists.apache.org/thread/2l1r16g79tpxd7fzrzr2q9oscwrjgljs

https://lists.apache.org/thread/2n14mk01bjc3lrsyhzrkwy8h86289mov

https://lists.apache.org/thread/5qs207krzg51jl3zs3cvnl5lt9njp8c3

https://lists.apache.org/thread/6m06gdqz4rxhy9g90qz9lyqx2gqmf13o

https://lists.apache.org/thread/7q08mz8bcbosp25wok7gr537zlp15mfz

https://lists.apache.org/thread/88c0h10yjb2b8201o1km3st71fs2zw2b

https://lists.apache.org/thread/drcq4chmt0btx86f17o47j17r378hzpw

https://lists.apache.org/thread/fzj8yzgfl53gclxrcdrnrx3grcpkq51j

https://lists.apache.org/thread/h2bjqm6g58z0j6893qzh728kdtk1byfy

https://lists.apache.org/thread/lr5d4tg6tf7j29jmw8wt242oowonjqpx

https://lists.apache.org/thread/pj63c3pf7kkp1xhr53do704fwj3t3htn

https://lists.apache.org/thread/trsnkxc2f21585zlt819blvchgl6oykb

Plugin Details

Severity: Critical

ID: 335183

File Name: apache_cxf_4_2_3.nasl

Version: 1.1

Type: Local

Agent: windows, macosx, unix

Family: Misc.

Published: 8/13/2026

Updated: 8/13/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.82

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-66909

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:apache:cxf

Required KB Items: installed_sw/Apache CXF

Patch Publication Date: 8/6/2026

Vulnerability Publication Date: 8/6/2026

Reference Information

CVE: CVE-2026-54225, CVE-2026-57817, CVE-2026-57818, CVE-2026-57819, CVE-2026-61466, CVE-2026-63687, CVE-2026-64958, CVE-2026-65432, CVE-2026-65583, CVE-2026-66909, CVE-2026-68079, CVE-2026-68481

CWE: 20, 294, 304, 345, 367, 400, 502, 611, 672, 770

IAVB: 2026-B-0224