https://seclists.org/oss-sec/2026/q3/478: CVE-2026-68079: Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code play
Published Aug 6, 2026
·Updated
Affected Software
3 affected components
Apache Apache CXF>4.2.0<4.2.3
Apache Apache CXF>4.0.0<4.1.8
Apache Apache CXF<3.6.12
Frequently Asked Questions
1
What is the severity of CVE-2026-68079?
CVE-2026-68079 is classified as a high severity vulnerability.
2
How do I fix CVE-2026-68079?
To fix CVE-2026-68079, upgrade to the latest version of Apache CXF where this issue is resolved.
3
What does CVE-2026-68079 affect in Apache CXF?
CVE-2026-68079 affects the DefaultEncryptingCodeDataProvider, allowing unlimited authorization code play.
4
Is CVE-2026-68079 exploitable without authentication?
Yes, CVE-2026-68079 can be exploited without authentication due to the nature of the vulnerability.
5
What is the impact of CVE-2026-68079 on application security?
CVE-2026-68079 can lead to unauthorized access and credential abuse, compromising application security.