CVE-2026-50632: Apache CXF: JNDI Injection Vulnerability in JMSConfigFactory
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
Other sources
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache CXFto a version that resolves this vulnerability.Fixed in 4.2.2Patch CVE-2026-50632 - Upgrade
Upgrade
Apache CXFto a version that resolves this vulnerability.Fixed in 4.1.7Patch CVE-2026-50632 - Upgrade
Upgrade
Apache CXFto a version that resolves this vulnerability.Fixed in 3.6.12Patch CVE-2026-50632
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50632?
CVE-2026-50632 has a high severity rating of 8.1 based on the CVSS 3.1 scoring system.
How do I fix CVE-2026-50632?
To remediate CVE-2026-50632, it's recommended to upgrade to the latest versions of Apache CXF that address this vulnerability.
What systems are affected by CVE-2026-50632?
CVE-2026-50632 affects Apache CXF installations where untrusted users can configure JMS.
What type of vulnerability is CVE-2026-50632?
CVE-2026-50632 is classified as a JNDI injection vulnerability specifically related to the JMSConfigFactory in Apache CXF.
Is there a known exploit for CVE-2026-50632?
While there is no specific exploit disclosed for CVE-2026-50632, it poses a risk for remote code execution if not properly mitigated.