Missing Critical Step in Authentication Affecting org.apache.cxf:cxf-rt-rs-security-oauth2 package, versions [,3.6.12)[4.0.0,4.1.8)[4.2.0,4.2.3)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.42% (36th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHECXF-19342250
  • published27 Aug 2026
  • disclosed6 Aug 2026
  • creditGuanping Zhang

Introduced: 6 Aug 2026

NewCVE-2026-61466  (opens in a new tab)
CWE-304  (opens in a new tab)

How to fix?

Upgrade org.apache.cxf:cxf-rt-rs-security-oauth2 to version 3.6.12, 4.1.8, 4.2.3 or higher.

Overview

org.apache.cxf:cxf-rt-rs-security-oauth2 is a services framework.

Affected versions of this package are vulnerable to Missing Critical Step in Authentication in the scope parameter processing of the OAuth2 Dynamic Client Registration endpoint. An attacker can obtain unauthorized access to privileged scopes by supplying arbitrary values in the registration request, which are accepted and stored without validation.

CVSS Base Scores

version 4.0
version 3.1