CVE-2026-40542: Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verification
Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache HttpClientto a version that resolves this vulnerability.Fixed in 5.6.1Patch CVE-2026-40542
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40542?
CVE-2026-40542 has been assigned a high severity rating due to its potential to allow unauthorized access through mutual authentication bypass.
How do I fix CVE-2026-40542?
To fix CVE-2026-40542, upgrade Apache HttpClient to version 5.7 or later where this vulnerability is addressed.
Who is affected by CVE-2026-40542?
CVE-2026-40542 affects users of Apache HttpClient version 5.6 when utilizing SCRAM-SHA-256 authentication.
What is the impact of CVE-2026-40542?
The impact of CVE-2026-40542 is that it can lead to unauthorized access as the client fails to properly verify mutual authentication.
When was CVE-2026-40542 published?
CVE-2026-40542 was published in April 2026.