CVE-2026-57818: Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider
A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache CXF (OAuth2)to a version that resolves this vulnerability.Fixed in 4.2.3 - Upgrade
Upgrade
Apache CXF (OAuth2)to a version that resolves this vulnerability.Fixed in 4.1.8 - Upgrade
Upgrade
Apache CXF (OAuth2)to a version that resolves this vulnerability.Fixed in 3.6.12
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57818?
CVE-2026-57818 has a risk score of 51, indicating a moderate severity level.
How do I fix CVE-2026-57818?
To fix CVE-2026-57818, upgrade to Apache CXF versions 4.2.3, 4.1.8, or 3.6.12.
What type of vulnerability is CVE-2026-57818?
CVE-2026-57818 is a race condition vulnerability found in the JCacheCodeDataProvider.
What impact does CVE-2026-57818 have on security?
CVE-2026-57818 allows attackers to redeem an authorization code multiple times, leading to multiple valid access tokens.
In which component of Apache CXF does CVE-2026-57818 occur?
CVE-2026-57818 occurs in the JCacheCodeDataProvider component of Apache CXF.